From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 6D8373DCDAA for ; Wed, 27 May 2026 12:21:15 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779884476; cv=none; b=XKEBghlrPE8YaCCHhTulV92ZGqVckXykbERFYtzx/MTaejdbDGco0mlyOhsYLa05thZ6FnOSB/zLZhPUnYGqQekUaywmOWSYP1WgdT6tLSiBLNyxCpp5J7z1ucuu/oPUCAS8yuywaXAyQOAJsp5jz3Vtq9snDAsrqvA0Q4qqRWY= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779884476; c=relaxed/simple; bh=2Eg0BPwki/bBnXKVsEt2fJv1K7MEthj7s+mCmS478Mc=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=uVOOt+WvT+YUAmlyJ1XCur8M5R30QZBGtBvGjKhqcJ5m1Z2YJyw5WFxrce5MhLLWba0fkBiz613etvmscKLApwTq+78ZDxImyOV0GMejgBhgGuu5TERhTJ7dgeUDJOsGYp6Q54OFilwPr/CslAENQEwo586oG4Bg9v0dgzov0Vo= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=2MqIiqTq; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="2MqIiqTq" Received: by smtp.kernel.org (Postfix) with ESMTPSA id BF6511F000E9; Wed, 27 May 2026 12:21:14 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1779884475; bh=hDBirSoI8U4OMQ6gDBU7GCR8BtNgm/1TnR8LwhMAW9s=; h=From:To:Cc:Subject:Date:Reply-To; b=2MqIiqTqoICVF1See03Z79GDvjp8ZzLoFh6Fem811Ll0D72VQyNJ4bfSMWG1QXJB2 zDfmlVeYvEDyAjt4c82uQR75hEMWGRucnNVw2PKlaGEaWwxvUtQ/UbpmNPfdPdpJ2Q FLgOMAN81L0scC1kqAddZN0CRKho2txo8knvTp6s= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-45873: netfilter: nft_set_rbtree: check for partial overlaps in anonymous sets Date: Wed, 27 May 2026 14:18:35 +0200 Message-ID: <2026052713-CVE-2026-45873-40e6@gregkh> X-Mailer: git-send-email 2.54.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=3840; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=pUSKWDPXrZUVhElhMR/tpUwfOqyIN3a0uSyoPDhHK6g=; b=owGbwMvMwCRo6H6F97bub03G02pJDFliD1l3vdgQy6t/n0ng7Z+NclsFfO6Gph26sEDe/I0gT 96VyLdHOmJZGASZGGTFFFm+bOM5ur/ikKKXoe1pmDmsTCBDGLg4BWAiDVIMC5oMhFy+SFXJ+fZy pefNjzGeJV1lxjCHz79qyZN9H0W+8DRE2im5vCzcp7wTAA== X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_rbtree: check for partial overlaps in anonymous sets Userspace provides an optimized representation in case intervals are adjacent, where the end element is omitted. The existing partial overlap detection logic skips anonymous set checks on start elements for this reason. However, it is possible to add intervals that overlap to this anonymous where two start elements with the same, eg. A-B, A-C where C < B. start end A B start end A C Restore the check on overlapping start elements to report an overlap. The Linux kernel CVE team has assigned CVE-2026-45873 to this issue. Affected and fixed versions =========================== Issue introduced in 5.10.166 with commit 4aacf3d78424293e318c616016865380b37b9cc5 and fixed in 5.10.252 with commit 7ca5813e1b21ef300e04593f47b073ef3217aac6 Issue introduced in 5.15.91 with commit 2bf1435fa19d2c58054391b3bba40d5510a5758c and fixed in 5.15.202 with commit 029e5f6a95e905b12d6bc20421be32a01e0eb311 Issue introduced in 6.1.9 with commit 318cb24a4c3fce8140afaf84e4d45fcb76fb280b and fixed in 6.1.165 with commit f1381ce0a1dd013610985e1c4260908163a427df Issue introduced in 6.2 with commit c9e6978e2725a7d4b6cd23b2facd3f11422c0643 and fixed in 6.6.128 with commit f1535d56fc3f6c625b7e0559c006bd0318791bb1 Issue introduced in 6.2 with commit c9e6978e2725a7d4b6cd23b2facd3f11422c0643 and fixed in 6.12.75 with commit 05feaf826390fd16f1deb89dd9412def3b2a280f Issue introduced in 6.2 with commit c9e6978e2725a7d4b6cd23b2facd3f11422c0643 and fixed in 6.18.14 with commit dad14d22dff1a191612acb98facceb303d0524a2 Issue introduced in 6.2 with commit c9e6978e2725a7d4b6cd23b2facd3f11422c0643 and fixed in 6.19.4 with commit e6497e06a102870803a59570d75ed2c36d7e11b3 Issue introduced in 6.2 with commit c9e6978e2725a7d4b6cd23b2facd3f11422c0643 and fixed in 7.0 with commit 4780ec142cbb24b794129d3080eee5cac2943ffc Issue introduced in 4.19.316 with commit 7ab87a326f20c52ff4d9972052d085be951c704b Issue introduced in 5.4.262 with commit 181859bdfb9734aca449512fccaee4cacce64aed Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-45873 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: net/netfilter/nft_set_rbtree.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/7ca5813e1b21ef300e04593f47b073ef3217aac6 https://git.kernel.org/stable/c/029e5f6a95e905b12d6bc20421be32a01e0eb311 https://git.kernel.org/stable/c/f1381ce0a1dd013610985e1c4260908163a427df https://git.kernel.org/stable/c/f1535d56fc3f6c625b7e0559c006bd0318791bb1 https://git.kernel.org/stable/c/05feaf826390fd16f1deb89dd9412def3b2a280f https://git.kernel.org/stable/c/dad14d22dff1a191612acb98facceb303d0524a2 https://git.kernel.org/stable/c/e6497e06a102870803a59570d75ed2c36d7e11b3 https://git.kernel.org/stable/c/4780ec142cbb24b794129d3080eee5cac2943ffc