CVE-2026-72350: netfilter: xt_u32: reject invalid shift counts
In the Linux kernel, the following vulnerability has been resolved:
netfilter: xtu32: reject invalid shift counts
u32matchit() executes rule-supplied shift operands on a 32-bit value. A malformed u32 rule can provide a shift count of 32 or more, triggering an undefined shift out-of-bounds during packet evaluation.
Validate XTU32LEFTSH and XTU32RIGHTSH operands in u32mtcheckentry() and reject malformed rules before they reach the packet path.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
If you use netfilter/iptables u32 rules, reject or block malformed u32 rules that would supply XT_U32_LEFTSH or XT_U32_RIGHTSH operands with invalid shift counts (e.g., shift count >= 32) so they are not evaluated in packet path.