Fedora Account System
Red Hat Associate
Red Hat Customer
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_queue: hold bridge skb->dev while queued br_pass_frame_up() rewrites skb->dev from the ingress port to the bridge master before queueing bridge LOCAL_IN packets. NFQUEUE only holds references on state.in/out and bridge physdevs, so a queued bridge packet can retain a freed bridge master in skb->dev until reinjection. When the verdict is reinjected later, br_netif_receive_skb() re-enters the receive path with skb->dev still pointing at the freed bridge master, triggering a use-after-free. Store skb->dev in the queue entry, hold a reference on it for the queue lifetime, and use the saved device when dropping queued packets during NETDEV_DOWN handling.
Upstream advisory: https://lore.kernel.org/linux-cve-announce/2026062426-CVE-2026-52912-9506@gregkh/T
FYI: A public exploit for CVE-2026-52912 has been released. Public exploit: https://github.com/NebuSec/CyberMeowfia/tree/main/security-research/Linux-CVE-2026-52912-Fedora-6.19.10-300 Relevant stable kernel fixes / reference patches: RHEL 8 reference (5.10 stable): https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=950d809f154dca04e5fbe5d3c8b9c5e44769cd57 RHEL 9 reference (5.15 stable): https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=a698ac8ab2561cf575d2d9f34095032651dd952e RHEL 10 reference (6.12 stable): https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=3823c27099cfe2482299065814adbaa771be9644 Demo video: https://x.com/nebusecurity/status/2091305715965239746
FYI, a working public exploit targeting RHEL 10.2 is now available. Kconfig suggests the following may be a possible mitigation: echo 'install bridge /bin/false' > /etc/modprobe.d/disable-bridge.conf This has not been fully validated as a mitigation.
Correction: Comment #6 was posted here by mistake. Please disregard it.
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:71330 https://access.redhat.com/errata/RHSA-2026:71330
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:71329 https://access.redhat.com/errata/RHSA-2026:71329
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:71700 https://access.redhat.com/errata/RHSA-2026:71700