Bug 2516459 (CVE-2026-72253)
| Summary: | CVE-2026-72253 kernel: netfilter: nf_conntrack_sip: validate skb_dst() before accessing it | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | CC: | rhel-process-autobot, watson-tool-maintainers |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in the Linux kernel's Netfilter Session Initiation Protocol (SIP) connection tracking helper. This vulnerability occurs when network traffic control (tc ingress) or Open vSwitch (openvswitch) subsystems are active, and a specific media handling feature (`sip_external_media`) is enabled. The system fails to properly verify network routing information, which can lead to the `sip_external_media` feature being unintentionally disabled, impacting its intended operation.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
OSIDB Bzimport
2026-08-15 06:13:39 UTC
|