CVE-2026-72349

Source
https://cve.org/CVERecord?id=CVE-2026-72349
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72349.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-72349
Downstream
Published
2026-08-15T05:55:52Z
Modified
2026-08-18T03:30:58Z
Summary
netfilter: xt_rateest: fix u64 truncation in xt_rateest_mt()
Details

In the Linux kernel, the following vulnerability has been resolved:

netfilter: xt_rateest: fix u64 truncation in xt_rateest_mt()

On links faster than 34 Gbps, where byte rate may exceed 2^32-1 ( 4.3 GBps), the comparison result becomes incorrect because the truncated value no longer reflects the actual estimator rate.

Fix by changing the local variables to u64.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72349.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
1c0d32fde5bdf1184bc274f864c09799278a1114
Fixed
77e9ba358d63fe2eb03c90d29ea85651d95cf2e6
Fixed
a3ba938f45cb00f6bf49d3aa3647df9b017f5f08
Fixed
bab305dd769d78074adca73505cc2509e1206bf2
Fixed
5da915fc159c6b4091669447588e520183969cca
Fixed
d5cc4c12a4b90bf099199c3c49ecda7e694f2a2b
Fixed
e702f6dd5d21e331f55fd9168c0210542008546d
Fixed
905a927b2e6fec7b174e9e5644d271047b61378f
Fixed
444853cd438201007da5359821adcc2995655ab1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72349.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.10.0
Fixed
5.10.261
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.212
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.178
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.145
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.97
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.40
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72349.json"