CVE-2026-72349

Summary

In the Linux kernel, the following vulnerability has been resolved:

netfilter: xt_rateest: fix u64 truncation in xt_rateest_mt()

On links faster than 34 Gbps, where byte rate may exceed 2^32-1 ( 4.3 GBps), the comparison result becomes incorrect because the truncated value no longer reflects the actual estimator rate.

Fix by changing the local variables to u64.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux1c0d32fde5bdf1184bc274f864c09799278a1114 < 77e9ba358d63fe2eb03c90d29ea85651d95cf2e6affected
LinuxLinux1c0d32fde5bdf1184bc274f864c09799278a1114 < a3ba938f45cb00f6bf49d3aa3647df9b017f5f08affected
LinuxLinux1c0d32fde5bdf1184bc274f864c09799278a1114 < bab305dd769d78074adca73505cc2509e1206bf2affected
LinuxLinux1c0d32fde5bdf1184bc274f864c09799278a1114 < 5da915fc159c6b4091669447588e520183969ccaaffected
LinuxLinux1c0d32fde5bdf1184bc274f864c09799278a1114 < d5cc4c12a4b90bf099199c3c49ecda7e694f2a2baffected
LinuxLinux1c0d32fde5bdf1184bc274f864c09799278a1114 < e702f6dd5d21e331f55fd9168c0210542008546daffected
LinuxLinux1c0d32fde5bdf1184bc274f864c09799278a1114 < 905a927b2e6fec7b174e9e5644d271047b61378faffected
LinuxLinux1c0d32fde5bdf1184bc274f864c09799278a1114 < 444853cd438201007da5359821adcc2995655ab1affected
LinuxLinux4.10affected
LinuxLinux0 < 4.10unaffected
LinuxLinux5.10.261 <= 5.10.*unaffected
LinuxLinux5.15.212 <= 5.15.*unaffected
LinuxLinux6.1.178 <= 6.1.*unaffected
LinuxLinux6.6.145 <= 6.6.*unaffected
LinuxLinux6.12.97 <= 6.12.*unaffected
LinuxLinux6.18.40 <= 6.18.*unaffected
LinuxLinux7.1.5 <= 7.1.*unaffected
LinuxLinux7.2 <= *unaffected

Weaknesses

References