A vulnerability in the Linux kernel's netfilter nft_set_rbtree component involves improper detection of partial overlaps in anonymous sets. (CVE-2026-45873)
A vulnerability in the Linux kernel's netfilter nft_set_rbtree component involves improper detection of partial overlaps in anonymous sets. The issue arises because the existing logic skips overlap checks on start elements when userspace provides an optimized representation for adjacent intervals. This can allow overlapping intervals with the same start element but different end elements to be added incorrectly. The vulnerability has been resolved by restoring the overlap check on start elements to properly detect and report overlaps.
AI Analysis
Technical Summary
The Linux kernel netfilter nft_set_rbtree component had a flaw in its partial overlap detection logic for anonymous sets. Userspace optimizes interval representation by omitting the end element for adjacent intervals, causing the kernel to skip overlap checks on start elements. This allowed intervals with the same start but overlapping end points (e.g., intervals A-B and A-C where C < B) to be added without detection. The fix restores the check on overlapping start elements to ensure such overlaps are detected and reported, preventing inconsistent interval sets.
Potential Impact
This vulnerability can cause the kernel to accept overlapping intervals in anonymous sets, potentially leading to inconsistent or unexpected behavior in netfilter operations. The CVSS vector indicates no confidentiality or integrity impact but a high impact on availability, suggesting possible denial of service or disruption scenarios. There are no known exploits in the wild.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since this is a kernel-level issue, applying official kernel updates when available is recommended to ensure the fix is applied. Until then, monitor vendor advisories for patches addressing this specific issue.
A vulnerability in the Linux kernel's netfilter nft_set_rbtree component involves improper detection of partial overlaps in anonymous sets. (CVE-2026-45873)
Description
A vulnerability in the Linux kernel's netfilter nft_set_rbtree component involves improper detection of partial overlaps in anonymous sets. The issue arises because the existing logic skips overlap checks on start elements when userspace provides an optimized representation for adjacent intervals. This can allow overlapping intervals with the same start element but different end elements to be added incorrectly. The vulnerability has been resolved by restoring the overlap check on start elements to properly detect and report overlaps.
CVSS v3.1
Score 5.5medium
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Linux kernel netfilter nft_set_rbtree component had a flaw in its partial overlap detection logic for anonymous sets. Userspace optimizes interval representation by omitting the end element for adjacent intervals, causing the kernel to skip overlap checks on start elements. This allowed intervals with the same start but overlapping end points (e.g., intervals A-B and A-C where C < B) to be added without detection. The fix restores the check on overlapping start elements to ensure such overlaps are detected and reported, preventing inconsistent interval sets.
Potential Impact
This vulnerability can cause the kernel to accept overlapping intervals in anonymous sets, potentially leading to inconsistent or unexpected behavior in netfilter operations. The CVSS vector indicates no confidentiality or integrity impact but a high impact on availability, suggesting possible denial of service or disruption scenarios. There are no known exploits in the wild.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since this is a kernel-level issue, applying official kernel updates when available is recommended to ensure the fix is applied. Until then, monitor vendor advisories for patches addressing this specific issue.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-9868-rgmf-pm96
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-45873"]
- Ecosystems
- []
- Database Specific Severity
- MODERATE
- Cvss Version
- 3.1
Threat ID: 6a3ef7f027e9c79719035c47
Added to database: 06/26/2026, 22:06:40 UTC
Last enriched: 06/26/2026, 22:50:36 UTC
Last updated: 07/31/2026, 19:24:47 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.