THREAT OPS › Threat News › [NVD] CVE-2026-43114 (CRITICAL 9.4) — In the Linux kernel, the following vulnerability has been resolved:
netfilter: nft_set_pipapo_avx2: don't return non-matching entry on expiry
New test case fails unexpectedly when avx2 matching functions are used.
The test first loads a ranomly generated pipapo set
with 'ipv4
[NVD] CVE-2026-43114 (CRITICAL 9.4) — In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_pipapo_avx2: don't return non-matching entry on expiry New test case fails unexpectedly when avx2 matching functions are used. The test first loads a ranomly generated pipapo set with 'ipv4
CVE-2026-43114 CVSS: 9.4 CRITICAL Published: 2026-05-06T10:16:25.163
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nft_set_pipapo_avx2: don't return non-matching entry on expiry
New test case fails unexpectedly when avx2 matching functions are used.
The test first loads a ranomly generated pipapo set with 'ipv4 . port' key, i.e. nft -f foo.
This works. Then,
Indicators of compromise
- CVE-2026-43114cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-43114