A vulnerability in the Linux kernel's netfilter nft_bitwise component allowed zero shift operands in left and right shift expressions during… (CVE-2026-46101)
A vulnerability in the Linux kernel's netfilter nft_bitwise component allowed zero shift operands in left and right shift expressions during initialization. This caused undefined behavior due to improper carry propagation logic when a zero shift was used. The issue was addressed by rejecting zero shift operands in the control plane alongside existing checks for shifts greater than or equal to 32, preventing malformed rules from reaching the packet processing path.
AI Analysis
Technical Summary
The Linux kernel's netfilter nft_bitwise feature had a vulnerability where zero shift operands in bitwise left and right shift expressions were not properly rejected during initialization. The carry propagation logic computed the carry using BITS_PER_TYPE(u32) - shift, and a zero shift operand effectively caused a 32-bit shift, which is undefined behavior. The fix involves rejecting zero shift operands in the control plane, in addition to existing checks for shifts >= 32, ensuring malformed rules do not propagate to the packet path.
Potential Impact
This vulnerability causes undefined behavior in the kernel's packet filtering logic, potentially leading to denial of service (crash or instability) as indicated by the CVSS vector's high availability impact. There is no impact on confidentiality or integrity. No known exploits are reported in the wild.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is confirmed, avoid deploying malformed nft_bitwise rules with zero shift operands. The vendor advisory from Microsoft Security Response Center should be monitored for updates.
A vulnerability in the Linux kernel's netfilter nft_bitwise component allowed zero shift operands in left and right shift expressions during… (CVE-2026-46101)
Description
A vulnerability in the Linux kernel's netfilter nft_bitwise component allowed zero shift operands in left and right shift expressions during initialization. This caused undefined behavior due to improper carry propagation logic when a zero shift was used. The issue was addressed by rejecting zero shift operands in the control plane alongside existing checks for shifts greater than or equal to 32, preventing malformed rules from reaching the packet processing path.
CVSS v3.1
Score 5.5medium
Affected software
pkg:github/microsoft/netfilterRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Linux kernel's netfilter nft_bitwise feature had a vulnerability where zero shift operands in bitwise left and right shift expressions were not properly rejected during initialization. The carry propagation logic computed the carry using BITS_PER_TYPE(u32) - shift, and a zero shift operand effectively caused a 32-bit shift, which is undefined behavior. The fix involves rejecting zero shift operands in the control plane, in addition to existing checks for shifts >= 32, ensuring malformed rules do not propagate to the packet path.
Potential Impact
This vulnerability causes undefined behavior in the kernel's packet filtering logic, potentially leading to denial of service (crash or instability) as indicated by the CVSS vector's high availability impact. There is no impact on confidentiality or integrity. No known exploits are reported in the wild.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is confirmed, avoid deploying malformed nft_bitwise rules with zero shift operands. The vendor advisory from Microsoft Security Response Center should be monitored for updates.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_vex
- Csaf Version
- 2.0
- Publisher
- Microsoft Security Response Center
- Advisory Id
- msrc_CVE-2026-46101
- Cve Count
- 1
- Additional Cves
- []
- Cvss Version
- 3.1
Threat ID: 6a18ab7fe29bf47b50288e43
Added to database: 05/28/2026, 20:54:23 UTC
Last enriched: 06/26/2026, 23:38:36 UTC
Last updated: 07/31/2026, 19:22:59 UTC
Views: 56
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.