Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-43916

Опубликовано: 12 мая 2026
Источник: ubuntu
Приоритет: medium
EPSS Низкий

Описание

pam_authnft is a PAM session module binding nftables firewall rules to authenticated sessions via cgroupv2 inodes. Prior to 0.2.0-alpha, a heap buffer over-read in peer_lookup_tcp (src/peer_lookup.c:134, prior to the fix) allowed a crafted NETLINK_SOCK_DIAG reply to slip past the message-size check, then dereference past the end of the allocation. This vulnerability is fixed in 0.2.0-alpha.

РелизСтатусПримечание
devel

not-affected

see notes
esm-infra-legacy/trusty

not-affected

see notes
esm-infra-legacy/xenial

not-affected

see notes
esm-infra/bionic

not-affected

see notes
esm-infra/focal

not-affected

see notes
esm-infra/xenial

ignored

end of ESM support, was not-affected (see notes
jammy

not-affected

see notes
noble

not-affected

see notes
questing

not-affected

see notes
resolute

not-affected

see notes

Показывать по

Ссылки на источники

EPSS

Процентиль: 18%
0.00263
Низкий

Связанные уязвимости

nvd
4 месяца назад

pam_authnft is a PAM session module binding nftables firewall rules to authenticated sessions via cgroupv2 inodes. Prior to 0.2.0-alpha, a heap buffer over-read in peer_lookup_tcp (src/peer_lookup.c:134, prior to the fix) allowed a crafted NETLINK_SOCK_DIAG reply to slip past the message-size check, then dereference past the end of the allocation. This vulnerability is fixed in 0.2.0-alpha.

EPSS

Процентиль: 18%
0.00263
Низкий