Answer in brief
CVE-2025-21826 records a Unknown severity vulnerability in netfilter: nf_tables: reject mismatching sum of field_len with set key length. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic), Siemens/SIMATIC S7-1500 TM MFP - BIOS (generic), Siemens/SIMATIC S7-1500 TM MFP - GNU/Linux subsystem (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2025-21826 records a Unknown severity vulnerability in netfilter: nf_tables: reject mismatching sum of field_len with set key length. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic), Siemens/SIMATIC S7-1500 TM MFP - BIOS (generic), Siemens/SIMATIC S7-1500 TM MFP - GNU/Linux subsystem (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic), Siemens/SIMATIC S7-1500 TM MFP - BIOS (generic), Siemens/SIMATIC S7-1500 TM MFP - GNU/Linux subsystem (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=2d4c0798a1ef8db15b3277697ac2def4eda42312 <6b467c8feac759f4c5c86d708beca2aa2b29584f || >=77be8c495a3f841e88b46508cc20d3d7d3289da3 <5083a7ae45003456c253e981b30a43f71230b4a3 || >=9cb084df01e198119de477ac691d682fb01e80f3 <2ac254343d3cf228ae0738b2615fedf85d000752 || >=dc45bb00e66a33de1abb29e3d587880e1d4d9a7e <82e491e085719068179ff6a5466b7387cc4bbf32 || >=3ce67e3793f48c1b9635beb9bb71116ca1e51b58 <49b7182b97bafbd5645414aff054b4a65d05823d || >=3ce67e3793f48c1b9635beb9bb71116ca1e51b58 <ab50d0eff4a939d20c37721fd9766347efcdb6f6 || >=3ce67e3793f48c1b9635beb9bb71116ca1e51b58 <1b9335a8000fb70742f7db10af314104b6ace220 || ff67e3e488090908dc015ba04d7407d8bd467f7e || >=5.10.209 <5.10.235 || >=5.15.148 <5.15.179 || >=6.1.75 <6.1.129 || >=6.6.14 <6.6.76 || >=6.7.2 <6.8 | 6b467c8feac759f4c5c86d708beca2aa2b29584f, 5083a7ae45003456c253e981b30a43f71230b4a3, 2ac254343d3cf228ae0738b2615fedf85d000752, 82e491e085719068179ff6a5466b7387cc4bbf32, 49b7182b97bafbd5645414aff054b4a65d05823d, ab50d0eff4a939d20c37721fd9766347efcdb6f6, 1b9335a8000fb70742f7db10af314104b6ace220, 5.10.235, 5.15.179, 6.1.129, 6.6.76, 6.8 |
| Linux/Linuxgeneric | 6.8 | Not reported |
| Siemens/SIMATIC S7-1500 TM MFP - BIOSgeneric | >=0 <* | * |
| Siemens/SIMATIC S7-1500 TM MFP - GNU/Linux subsystemgeneric | >=0 <* | * |
Published upstream
Mar 6, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: reject mismatching sum of field_len with set key length The field length description provides the length of each separated key field in the concatenation, each field gets rounded up to 32-bits to calculate the pipapo rule width from pipapo_init(). The set key length provides the total size of the key aligned to 32-bits. Register-based arithmetics still allows for combining mismatching set key length and field length description, eg. set key length 10 and field description [ 5, 4 ] leading to pipapo width of 12.
Quoted source text, attributed separately from HOL analysis.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic), Siemens/SIMATIC S7-1500 TM MFP - BIOS (generic), Siemens/SIMATIC S7-1500 TM MFP - GNU/Linux subsystem (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=2d4c0798a1ef8db15b3277697ac2def4eda42312 <6b467c8feac759f4c5c86d708beca2aa2b29584f || >=77be8c495a3f841e88b46508cc20d3d7d3289da3 <5083a7ae45003456c253e981b30a43f71230b4a3 || >=9cb084df01e198119de477ac691d682fb01e80f3 <2ac254343d3cf228ae0738b2615fedf85d000752 || >=dc45bb00e66a33de1abb29e3d587880e1d4d9a7e <82e491e085719068179ff6a5466b7387cc4bbf32 || >=3ce67e3793f48c1b9635beb9bb71116ca1e51b58 <49b7182b97bafbd5645414aff054b4a65d05823d || >=3ce67e3793f48c1b9635beb9bb71116ca1e51b58 <ab50d0eff4a939d20c37721fd9766347efcdb6f6 || >=3ce67e3793f48c1b9635beb9bb71116ca1e51b58 <1b9335a8000fb70742f7db10af314104b6ace220 || ff67e3e488090908dc015ba04d7407d8bd467f7e || >=5.10.209 <5.10.235 || >=5.15.148 <5.15.179 || >=6.1.75 <6.1.129 || >=6.6.14 <6.6.76 || >=6.7.2 <6.8 | 6b467c8feac759f4c5c86d708beca2aa2b29584f, 5083a7ae45003456c253e981b30a43f71230b4a3, 2ac254343d3cf228ae0738b2615fedf85d000752, 82e491e085719068179ff6a5466b7387cc4bbf32, 49b7182b97bafbd5645414aff054b4a65d05823d, ab50d0eff4a939d20c37721fd9766347efcdb6f6, 1b9335a8000fb70742f7db10af314104b6ace220, 5.10.235, 5.15.179, 6.1.129, 6.6.76, 6.8 |
| Linux/Linuxgeneric | 6.8 | Not reported |
| Siemens/SIMATIC S7-1500 TM MFP - BIOSgeneric | >=0 <* | * |
| Siemens/SIMATIC S7-1500 TM MFP - GNU/Linux subsystemgeneric | >=0 <* | * |
Published upstream
Mar 6, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: reject mismatching sum of field_len with set key length The field length description provides the length of each separated key field in the concatenation, each field gets rounded up to 32-bits to calculate the pipapo rule width from pipapo_init(). The set key length provides the total size of the key aligned to 32-bits. Register-based arithmetics still allows for combining mismatching set key length and field length description, eg. set key length 10 and field description [ 5, 4 ] leading to pipapo width of 12.
Quoted source text, attributed separately from HOL analysis.