In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: strictly check for maximum number of actions The maximum… (CVE-2026-43329)
In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: strictly check for maximum number of actions The maximum number of flowtable hardware offload actions in IPv6 is: * ethernet mangling (4 payload actions, 2 for each ethernet address) * SNAT (4 payload actions) * DNAT (4 payload actions) * Double VLAN (4 vlan actions, 2 for popping vlan, and 2 for pushing) for QinQ. * Redirect (1 action) Which makes 17, while the maximum is 16. But act_ct supports for tunnels actions too. Note that payload action operates at 32-bit word level, so mangling an IPv6 address takes 4 payload actions. Update flow_action_entry_next() calls to check for the maximum number of supported actions. While at it, rise the maximum number of actions per flow from 16 to 24 so this works fine with IPv6 setups.
AI Analysis
Technical Summary
This advisory covers multiple security fixes for Red Hat OpenShift Container Platform, specifically addressing kernel vulnerabilities. CVE-2026-43329 involves netfilter flowtable where the maximum number of actions was not strictly checked, potentially leading to security issues. CVE-2026-46323 is a use-after-free vulnerability in the Linux kernel's net/gro subsystem caused by improper handling of zerocopy skbs. CVE-2026-53359 addresses a KVM x86 shadow paging use-after-free due to unexpected role handling. These vulnerabilities affect kernel components used by OpenShift Container Platform versions 4.18 and 4.21. Red Hat has released updated packages and container images that fix these vulnerabilities. Users are advised to upgrade their clusters using the OpenShift CLI or web console following Red Hat's documented upgrade procedures.
Potential Impact
The vulnerabilities impact the Linux kernel components used in Red Hat OpenShift Container Platform, potentially allowing local attackers with low privileges to cause use-after-free conditions, leading to system crashes or escalation of privileges. The CVSS 3.1 vector for CVE-2026-43329 indicates local attack vector with low complexity, requiring low privileges, no user interaction, and impacts confidentiality, integrity, and availability at a high level. These issues could compromise the security and stability of the affected OpenShift clusters if exploited.
Mitigation Recommendations
Red Hat has released official fixes for these vulnerabilities in updated packages and container images for OpenShift Container Platform versions 4.18 and 4.21. Users should upgrade to the latest available versions through the OpenShift CLI (oc) or web console as soon as updates are available in their release channels. Detailed upgrade instructions are provided in Red Hat's official documentation. No alternative mitigations or workarounds are indicated in the vendor advisory. Patch status is confirmed as fixed in the updated releases.
In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: strictly check for maximum number of actions The maximum… (CVE-2026-43329)
Description
In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: strictly check for maximum number of actions The maximum number of flowtable hardware offload actions in IPv6 is: * ethernet mangling (4 payload actions, 2 for each ethernet address) * SNAT (4 payload actions) * DNAT (4 payload actions) * Double VLAN (4 vlan actions, 2 for popping vlan, and 2 for pushing) for QinQ. * Redirect (1 action) Which makes 17, while the maximum is 16. But act_ct supports for tunnels actions too. Note that payload action operates at 32-bit word level, so mangling an IPv6 address takes 4 payload actions. Update flow_action_entry_next() calls to check for the maximum number of supported actions. While at it, rise the maximum number of actions per flow from 16 to 24 so this works fine with IPv6 setups.
CVSS v3.1
Score 7.8high
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This advisory covers multiple security fixes for Red Hat OpenShift Container Platform, specifically addressing kernel vulnerabilities. CVE-2026-43329 involves netfilter flowtable where the maximum number of actions was not strictly checked, potentially leading to security issues. CVE-2026-46323 is a use-after-free vulnerability in the Linux kernel's net/gro subsystem caused by improper handling of zerocopy skbs. CVE-2026-53359 addresses a KVM x86 shadow paging use-after-free due to unexpected role handling. These vulnerabilities affect kernel components used by OpenShift Container Platform versions 4.18 and 4.21. Red Hat has released updated packages and container images that fix these vulnerabilities. Users are advised to upgrade their clusters using the OpenShift CLI or web console following Red Hat's documented upgrade procedures.
Potential Impact
The vulnerabilities impact the Linux kernel components used in Red Hat OpenShift Container Platform, potentially allowing local attackers with low privileges to cause use-after-free conditions, leading to system crashes or escalation of privileges. The CVSS 3.1 vector for CVE-2026-43329 indicates local attack vector with low complexity, requiring low privileges, no user interaction, and impacts confidentiality, integrity, and availability at a high level. These issues could compromise the security and stability of the affected OpenShift clusters if exploited.
Mitigation Recommendations
Red Hat has released official fixes for these vulnerabilities in updated packages and container images for OpenShift Container Platform versions 4.18 and 4.21. Users should upgrade to the latest available versions through the OpenShift CLI (oc) or web console as soon as updates are available in their release channels. Detailed upgrade instructions are provided in Red Hat's official documentation. No alternative mitigations or workarounds are indicated in the vendor advisory. Patch status is confirmed as fixed in the updated releases.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-45q4-4828-537r
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-43329"]
- Ecosystems
- []
- Database Specific Severity
- HIGH
- Cvss Version
- 3.1
Threat ID: 6a46ecfa27e9c79719444073
Added to database: 07/02/2026, 22:58:02 UTC
Last enriched: 07/30/2026, 15:22:41 UTC
Last updated: 07/31/2026, 19:24:49 UTC
Views: 27
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.