{"id":"CVE-2025-38162","title":"netfilter: nft_set_pipapo: prevent overflow in lookup table allocation","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nft_set_pipapo: prevent overflow in lookup table allocation\n\nWhen calculating the lookup table size, ensure the following\nmultiplication does not overflow:\n\n…","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cvssSource":"cna","vendor":"Linux","product":"Linux","affected":["Linux >= 3c4287f62044a90e73a561aa05fc46e62da173da < 91edc076439c9e2f34b176149f1c84a47a8ec32f","Linux >= 3c4287f62044a90e73a561aa05fc46e62da173da < a9e757473561da93c6a4136f0e59aba91ec777fc","Linux >= 3c4287f62044a90e73a561aa05fc46e62da173da < c1360ac8156c0a3f2385baef91d8d26fd9d39701","Linux >= 3c4287f62044a90e73a561aa05fc46e62da173da < 43fe1181f738295624696ae9ff611790edb65b5e","Linux >= 3c4287f62044a90e73a561aa05fc46e62da173da < 4c5c6aa9967dbe55bd017bb509885928d0f31206","Linux 5.6"],"published":"2025-07-03","updated":"2026-09-08","sourceUpdated":"2026-09-08T08:41:44.717Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2025-38162","references":[{"url":"https://git.kernel.org/stable/c/91edc076439c9e2f34b176149f1c84a47a8ec32f"},{"url":"https://git.kernel.org/stable/c/a9e757473561da93c6a4136f0e59aba91ec777fc"},{"url":"https://git.kernel.org/stable/c/c1360ac8156c0a3f2385baef91d8d26fd9d39701"},{"url":"https://git.kernel.org/stable/c/43fe1181f738295624696ae9ff611790edb65b5e"},{"url":"https://git.kernel.org/stable/c/4c5c6aa9967dbe55bd017bb509885928d0f31206"}],"tags":["cve.org"],"epss":0.00156,"epssPercentile":0.05127,"ingestedAt":"2026-09-08T15:33:26.997Z","slug":"CVE-2025-38162","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nft_set_pipapo: prevent overflow in lookup table allocation\n\nWhen calculating the lookup table size, ensure the following\nmultiplication does not overflow:\n\n- desc->field_len[] maximum value is U8_MAX multiplied by\n  NFT_PIPAPO_GROUPS_PER_BYTE(f) that can be 2, worst case.\n- NFT_PIPAPO_BUCKETS(f->bb) is 2^8, worst case.\n- sizeof(unsigned long), from sizeof(*f->lt), lt in\n  struct nft_pipapo_field.\n\nThen, use check_mul_overflow() to multiply by bucket size and then use\ncheck_add_overflow() to the alignment for avx2 (if needed). Finally, add\nlt_size_check_overflow() helper and use it to consolidate this.\n\nWhile at it, replace leftover allocation using the GFP_KERNEL to\nGFP_KERNEL_ACCOUNT for consistency, in pipapo_resize().\n\n## Affected\n\n- `Linux >= 3c4287f62044a90e73a561aa05fc46e62da173da < 91edc076439c9e2f34b176149f1c84a47a8ec32f`\n- `Linux >= 3c4287f62044a90e73a561aa05fc46e62da173da < a9e757473561da93c6a4136f0e59aba91ec777fc`\n- `Linux >= 3c4287f62044a90e73a561aa05fc46e62da173da < c1360ac8156c0a3f2385baef91d8d26fd9d39701`\n- `Linux >= 3c4287f62044a90e73a561aa05fc46e62da173da < 43fe1181f738295624696ae9ff611790edb65b5e`\n- `Linux >= 3c4287f62044a90e73a561aa05fc46e62da173da < 4c5c6aa9967dbe55bd017bb509885928d0f31206`\n- `Linux 5.6`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":43,"depthScoreParts":{"impact":42.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}