THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-43114 (CRITICAL 9.4) — In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_pipapo_avx2: don't return non-matching entry on expiry New test case fails unexpectedly when avx2 matching functions are used. The test first loads a ranomly generated pipapo set with 'ipv4

[NVD] CVE-2026-43114 (CRITICAL 9.4) — In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_pipapo_avx2: don't return non-matching entry on expiry New test case fails unexpectedly when avx2 matching functions are used. The test first loads a ranomly generated pipapo set with 'ipv4

lownvdPublished 2026-05-06

CVE-2026-43114 CVSS: 9.4 CRITICAL Published: 2026-05-06T10:16:25.163

In the Linux kernel, the following vulnerability has been resolved:

netfilter: nft_set_pipapo_avx2: don't return non-matching entry on expiry

New test case fails unexpectedly when avx2 matching functions are used.

The test first loads a ranomly generated pipapo set with 'ipv4 . port' key, i.e. nft -f foo.

This works. Then,

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-43114