netfilter: flowtable: strictly check for maximum number of actions
Published May 8, 2026
7.8
HIGHCVSS 3.1
EPSS 0.19%
Description
The maximum number of flowtable hardware offload actions in IPv6 is:
* ethernet mangling (4 payload actions, 2 for each ethernet address) * SNAT (4 payload actions) * DNAT (4 payload actions) * Double VLAN (4 vlan actions, 2 for popping vlan, and 2 for pushing) for QinQ. * Redirect (1 action)
Which makes 17, while the maximum is 16. But act_ct supports for tunnels actions too. Note that payload action operates at 32-bit word level, so mangling an IPv6 address takes 4 payload actions.
Update flow_action_entry_next() calls to check for the maximum number of supported actions.
While at it, rise the maximum number of actions per flow from 16 to 24 so this works fine with IPv6 setups.
Affected products
-
Affected
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
-
Affected
- 5.5
Unaffected
- ≥ 0, < 5.5
- ≥ 5.15.203, ≤ 5.15.*
- ≥ 6.1.168, ≤ 6.1.*
- ≥ 6.12.81, ≤ 6.12.*
- ≥ 6.18.22, ≤ 6.18.*
- ≥ 6.19.12, ≤ 6.19.*
- ≥ 6.6.134, ≤ 6.6.*
- 7.0
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
- ≥ 5.5 · < 5.15.203
- ≥ 5.16 · < 6.1.168
- ≥ 6.2 · < 6.6.134
- ≥ 6.7 · < 6.12.81
- ≥ 6.13 · < 6.18.22
- ≥ 6.19 · < 6.19.12
- 7.0
- 7.0
- 7.0
- 7.0
- 7.0
- 7.0
No data.
Red Hat Enterprise Linux 10
kernel-0:6.12.0-211.20.1.el10_2
Fixed · RHSA-2026:23329
Red Hat Enterprise Linux 10
kpatch-patch
Fixed · RHSA-2026:55618
Red Hat Enterprise Linux 10.0 Extended Update Support
kernel-0:6.12.0-55.84.1.el10_0
Fixed · RHSA-2026:33215
Red Hat Enterprise Linux 8
kernel-0:4.18.0-553.134.1.el8_10
Fixed · RHSA-2026:26427
Red Hat Enterprise Linux 8
kernel-rt-0:4.18.0-553.134.1.rt7.475.el8_10
Fixed · RHSA-2026:26428
Red Hat Enterprise Linux 8
kpatch-patch
Fixed · RHSA-2026:55762
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
kernel-0:4.18.0-305.197.1.el8_4
Fixed · RHSA-2026:35896
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
kernel-0:4.18.0-305.197.1.el8_4
Fixed · RHSA-2026:35896
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
kernel-0:4.18.0-372.198.1.el8_6
Fixed · RHSA-2026:33899
Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On
kernel-0:4.18.0-372.198.1.el8_6
Fixed · RHSA-2026:33899
Red Hat Enterprise Linux 8.8 Telecommunications Update Service
kernel-0:4.18.0-477.150.1.el8_8
Fixed · RHSA-2026:35863
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
kernel-0:4.18.0-477.150.1.el8_8
Fixed · RHSA-2026:35863
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
kpatch-patch
Fixed · RHSA-2026:55761
Red Hat Enterprise Linux 9
kernel-0:5.14.0-687.19.1.el9_8
Fixed · RHSA-2026:30848
Red Hat Enterprise Linux 9
kernel-0:5.14.0-687.19.1.el9_8
Fixed · RHSA-2026:30848
Red Hat Enterprise Linux 9
kpatch-patch
Fixed · RHSA-2026:55763
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions
kernel-0:5.14.0-284.178.1.el9_2
Fixed · RHSA-2026:34095
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions
kernel-rt-0:5.14.0-284.178.1.rt14.463.el9_2
Fixed · RHSA-2026:33900
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions
kpatch-patch
Fixed · RHSA-2026:55837
Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions
kernel-0:5.14.0-427.134.1.el9_4
Fixed · RHSA-2026:27713
Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions
kpatch-patch
Fixed · RHSA-2026:56224
Red Hat Enterprise Linux 9.6 Extended Update Support
kernel-0:5.14.0-570.125.1.el9_6
Fixed · RHSA-2026:34094
Red Hat Enterprise Linux 9.6 Extended Update Support
kpatch-patch
Fixed · RHSA-2026:56225
Red Hat OpenShift Container Platform 4.12
rhcos-412.86.202607211933-0
Fixed · RHSA-2026:47702
Red Hat OpenShift Container Platform 4.13
rhcos-413.92.202608111330-0
Fixed · RHSA-2026:54187
Red Hat OpenShift Container Platform 4.14
rhcos-414.92.202607210313-0
Fixed · RHSA-2026:43252
Red Hat OpenShift Container Platform 4.15
rhcos-415.92.202608180329-0
Fixed · RHSA-2026:56911
Red Hat OpenShift Container Platform 4.16
rhcos-416.94.202608150307-0
Fixed · RHSA-2026:56853
Red Hat OpenShift Container Platform 4.17
rhcos-417.94.202607240132-0
Fixed · RHSA-2026:47727
Red Hat OpenShift Container Platform 4.18
rhcos-418.94.202607211754-0
Fixed · RHSA-2026:44230
Red Hat OpenShift Container Platform 4.19
rhcos-4.19.9.6.202607220857-0
Fixed · RHSA-2026:44231
Red Hat OpenShift Container Platform 4.20
rhcos-4.20.9.6.202607221038-0
Fixed · RHSA-2026:44259
Red Hat OpenShift Container Platform 4.21
rhcos-4.21.9.6.202607221317-0
Fixed · RHSA-2026:44262
Red Hat OpenShift Container Platform 4.22
rhcos-4.22.9.8.202607152026-0
Fixed · RHSA-2026:40764
Red Hat Enterprise Linux 10
libkrun
Not affected
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Affected
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-9
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel-0:6.12.0-211.20.1.el10_2 | Fixed | RHSA-2026:23329 |
| Red Hat Enterprise Linux 10 | kpatch-patch | Fixed | RHSA-2026:55618 |
| Red Hat Enterprise Linux 10.0 Extended Update Support | kernel-0:6.12.0-55.84.1.el10_0 | Fixed | RHSA-2026:33215 |
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-553.134.1.el8_10 | Fixed | RHSA-2026:26427 |
| Red Hat Enterprise Linux 8 | kernel-rt-0:4.18.0-553.134.1.rt7.475.el8_10 | Fixed | RHSA-2026:26428 |
| Red Hat Enterprise Linux 8 | kpatch-patch | Fixed | RHSA-2026:55762 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | kernel-0:4.18.0-305.197.1.el8_4 | Fixed | RHSA-2026:35896 |
| Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | kernel-0:4.18.0-305.197.1.el8_4 | Fixed | RHSA-2026:35896 |
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | kernel-0:4.18.0-372.198.1.el8_6 | Fixed | RHSA-2026:33899 |
| Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On | kernel-0:4.18.0-372.198.1.el8_6 | Fixed | RHSA-2026:33899 |
| Red Hat Enterprise Linux 8.8 Telecommunications Update Service | kernel-0:4.18.0-477.150.1.el8_8 | Fixed | RHSA-2026:35863 |
| Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | kernel-0:4.18.0-477.150.1.el8_8 | Fixed | RHSA-2026:35863 |
| Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | kpatch-patch | Fixed | RHSA-2026:55761 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-687.19.1.el9_8 | Fixed | RHSA-2026:30848 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-687.19.1.el9_8 | Fixed | RHSA-2026:30848 |
| Red Hat Enterprise Linux 9 | kpatch-patch | Fixed | RHSA-2026:55763 |
| Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | kernel-0:5.14.0-284.178.1.el9_2 | Fixed | RHSA-2026:34095 |
| Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | kernel-rt-0:5.14.0-284.178.1.rt14.463.el9_2 | Fixed | RHSA-2026:33900 |
| Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | kpatch-patch | Fixed | RHSA-2026:55837 |
| Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions | kernel-0:5.14.0-427.134.1.el9_4 | Fixed | RHSA-2026:27713 |
| Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions | kpatch-patch | Fixed | RHSA-2026:56224 |
| Red Hat Enterprise Linux 9.6 Extended Update Support | kernel-0:5.14.0-570.125.1.el9_6 | Fixed | RHSA-2026:34094 |
| Red Hat Enterprise Linux 9.6 Extended Update Support | kpatch-patch | Fixed | RHSA-2026:56225 |
| Red Hat OpenShift Container Platform 4.12 | rhcos-412.86.202607211933-0 | Fixed | RHSA-2026:47702 |
| Red Hat OpenShift Container Platform 4.13 | rhcos-413.92.202608111330-0 | Fixed | RHSA-2026:54187 |
| Red Hat OpenShift Container Platform 4.14 | rhcos-414.92.202607210313-0 | Fixed | RHSA-2026:43252 |
| Red Hat OpenShift Container Platform 4.15 | rhcos-415.92.202608180329-0 | Fixed | RHSA-2026:56911 |
| Red Hat OpenShift Container Platform 4.16 | rhcos-416.94.202608150307-0 | Fixed | RHSA-2026:56853 |
| Red Hat OpenShift Container Platform 4.17 | rhcos-417.94.202607240132-0 | Fixed | RHSA-2026:47727 |
| Red Hat OpenShift Container Platform 4.18 | rhcos-418.94.202607211754-0 | Fixed | RHSA-2026:44230 |
| Red Hat OpenShift Container Platform 4.19 | rhcos-4.19.9.6.202607220857-0 | Fixed | RHSA-2026:44231 |
| Red Hat OpenShift Container Platform 4.20 | rhcos-4.20.9.6.202607221038-0 | Fixed | RHSA-2026:44259 |
| Red Hat OpenShift Container Platform 4.21 | rhcos-4.21.9.6.202607221317-0 | Fixed | RHSA-2026:44262 |
| Red Hat OpenShift Container Platform 4.22 | rhcos-4.22.9.8.202607152026-0 | Fixed | RHSA-2026:40764 |
| Red Hat Enterprise Linux 10 | libkrun | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-9 | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
References (44)
- https://access.redhat.com/errata/RHSA-2026:23329
- https://access.redhat.com/errata/RHSA-2026:26427
- https://access.redhat.com/errata/RHSA-2026:26428
- https://access.redhat.com/errata/RHSA-2026:27713
- https://access.redhat.com/errata/RHSA-2026:30848
- https://access.redhat.com/errata/RHSA-2026:33215
- https://access.redhat.com/errata/RHSA-2026:33899
- https://access.redhat.com/errata/RHSA-2026:33900
- https://access.redhat.com/errata/RHSA-2026:34094
- https://access.redhat.com/errata/RHSA-2026:34095
- https://access.redhat.com/errata/RHSA-2026:35863
- https://access.redhat.com/errata/RHSA-2026:35896
- https://access.redhat.com/errata/RHSA-2026:40764
- https://access.redhat.com/errata/RHSA-2026:43252
- https://access.redhat.com/errata/RHSA-2026:44230
- https://access.redhat.com/errata/RHSA-2026:44231
- https://access.redhat.com/errata/RHSA-2026:44259
- https://access.redhat.com/errata/RHSA-2026:44262
- https://access.redhat.com/errata/RHSA-2026:47702
- https://access.redhat.com/errata/RHSA-2026:47727
- https://access.redhat.com/errata/RHSA-2026:54187
- https://access.redhat.com/errata/RHSA-2026:55618
- https://access.redhat.com/errata/RHSA-2026:55761
- https://access.redhat.com/errata/RHSA-2026:55762
- https://access.redhat.com/errata/RHSA-2026:55763
- https://access.redhat.com/errata/RHSA-2026:55837
- https://access.redhat.com/errata/RHSA-2026:56224
- https://access.redhat.com/errata/RHSA-2026:56225
- https://access.redhat.com/errata/RHSA-2026:56853
- https://access.redhat.com/errata/RHSA-2026:56911
- https://access.redhat.com/security/cve/CVE-2026-43329 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2468124 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-28613 Advisory
- https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-43329.mbox
- https://git.kernel.org/stable/c/504c9456699dcf4d15195ef34a0fa94a80bfc877 Patch
- https://git.kernel.org/stable/c/5382bb03e9c33b089d60788478b922a2dca284cc Patch
- https://git.kernel.org/stable/c/57c78bd2e2dd08897acd35b2bf8bcef322e36f5e Patch
- https://git.kernel.org/stable/c/76522fcdbc3a02b568f5d957f7e66fc194abb893 Patch
- https://git.kernel.org/stable/c/879959a7a2be814dd57568655eafa3d8f4d0309e Patch
- https://git.kernel.org/stable/c/ead66c77303f760f6c30be96e2e20d5a77cef614 Patch
- https://git.kernel.org/stable/c/fe9018d3e94329f1951b00805a8640bc06f56ead Patch
- https://nvd.nist.gov/vuln/detail/CVE-2026-43329
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-43329.json
- https://www.cve.org/CVERecord?id=CVE-2026-43329
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub
No data