Bug 2516606 (CVE-2026-72320)
| Summary: | CVE-2026-72320 kernel: netfilter: nft_lookup: fix catchall element handling with inverted lookups | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | unspecified | CC: | rhel-process-autobot, watson-tool-maintainers |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in the Linux kernel's `netfilter` component, specifically within the `nft_lookup` functionality. This issue arises from incorrect handling of 'catchall' elements during 'inverted lookups' in the `nft_lookup_eval()` function. Due to a logic error where the lookup result is not recomputed, network packets may be wrongly matched or skipped, leading to incorrect application of network filtering rules. This could potentially allow unauthorized network traffic or cause denial of service by incorrectly dropping legitimate traffic.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
OSIDB Bzimport
2026-08-15 06:21:34 UTC
|