In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: strictly check for maximum number of actions The maximum… (CVE-2026-43329)
In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: strictly check for maximum number of actions The maximum number of flowtable hardware offload actions in IPv6 is: * ethernet mangling (4 payload actions, 2 for each ethernet address) * SNAT (4 payload actions) * DNAT (4 payload actions) * Double VLAN (4 vlan actions, 2 for popping vlan, and 2 for pushing) for QinQ. * Redirect (1 action) Which makes 17, while the maximum is 16. But act_ct supports for tunnels actions too. Note that payload action operates at 32-bit word level, so mangling an IPv6 address takes 4 payload actions. Update flow_action_entry_next() calls to check for the maximum number of supported actions. While at it, rise the maximum number of actions per flow from 16 to 24 so this works fine with IPv6 setups.
AI Analysis
Technical Summary
CVE-2026-43329 is a vulnerability in the Linux kernel netfilter flowtable component where the system did not strictly enforce the maximum number of hardware offload actions for IPv6. The maximum number of flowtable actions was 16, but the system could process 17 or more due to lack of strict checks, leading to potential resource exhaustion or denial of service. The fix involved updating flow_action_entry_next() to enforce the maximum number of supported actions and increasing the maximum allowed actions per flow from 16 to 24 to support IPv6 configurations. Red Hat has released patches for affected OpenShift Container Platform versions and Linux kernel versions to address this issue.
Potential Impact
The vulnerability allows local users with low privileges to cause high impact on confidentiality, integrity, and availability by triggering system instability or denial of service through resource exhaustion in the netfilter flowtable component. The CVSS v3.1 base score is 7.8 (high severity), reflecting low attack complexity and privileges required, no user interaction, and high impact on confidentiality, integrity, and availability.
Mitigation Recommendations
A security update fixing this vulnerability is available and has been released for Red Hat OpenShift Container Platform 4.21.26 and Linux kernel versions >=4.21.0 <4.21.26. Users are advised to upgrade to these fixed versions as soon as possible. No vendor advisory indicates any alternative mitigations or that no action is required. Follow vendor instructions for upgrading clusters or systems to apply the fix.
In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: strictly check for maximum number of actions The maximum… (CVE-2026-43329)
Description
In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: strictly check for maximum number of actions The maximum number of flowtable hardware offload actions in IPv6 is: * ethernet mangling (4 payload actions, 2 for each ethernet address) * SNAT (4 payload actions) * DNAT (4 payload actions) * Double VLAN (4 vlan actions, 2 for popping vlan, and 2 for pushing) for QinQ. * Redirect (1 action) Which makes 17, while the maximum is 16. But act_ct supports for tunnels actions too. Note that payload action operates at 32-bit word level, so mangling an IPv6 address takes 4 payload actions. Update flow_action_entry_next() calls to check for the maximum number of supported actions. While at it, rise the maximum number of actions per flow from 16 to 24 so this works fine with IPv6 setups.
CVSS v3.1
Score 7.8high
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-43329 is a vulnerability in the Linux kernel netfilter flowtable component where the system did not strictly enforce the maximum number of hardware offload actions for IPv6. The maximum number of flowtable actions was 16, but the system could process 17 or more due to lack of strict checks, leading to potential resource exhaustion or denial of service. The fix involved updating flow_action_entry_next() to enforce the maximum number of supported actions and increasing the maximum allowed actions per flow from 16 to 24 to support IPv6 configurations. Red Hat has released patches for affected OpenShift Container Platform versions and Linux kernel versions to address this issue.
Potential Impact
The vulnerability allows local users with low privileges to cause high impact on confidentiality, integrity, and availability by triggering system instability or denial of service through resource exhaustion in the netfilter flowtable component. The CVSS v3.1 base score is 7.8 (high severity), reflecting low attack complexity and privileges required, no user interaction, and high impact on confidentiality, integrity, and availability.
Mitigation Recommendations
A security update fixing this vulnerability is available and has been released for Red Hat OpenShift Container Platform 4.21.26 and Linux kernel versions >=4.21.0 <4.21.26. Users are advised to upgrade to these fixed versions as soon as possible. No vendor advisory indicates any alternative mitigations or that no action is required. Follow vendor instructions for upgrading clusters or systems to apply the fix.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-45q4-4828-537r
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-43329"]
- Database Specific Severity
- HIGH
- Cvss Version
- 3.1
Threat ID: 6a46ecfa27e9c79719444073
Added to database: 07/02/2026, 22:58:02 UTC
Last enriched: 08/06/2026, 23:32:07 UTC
Last updated: 09/12/2026, 22:01:33 UTC
Views: 64
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.