Bug 2492105 (CVE-2026-52912) - CVE-2026-52912 kernel: netfilter: nf_queue: hold bridge skb->dev while queued
Summary: CVE-2026-52912 kernel: netfilter: nf_queue: hold bridge skb->dev while queued
Keywords:
Status: NEW
Alias: CVE-2026-52912
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-06-24 08:02 UTC by OSIDB Bzimport
Modified: 2026-09-25 06:12 UTC (History)
3 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2026:71329 0 None None None 2026-09-24 05:25:17 UTC
Red Hat Product Errata RHSA-2026:71330 0 None None None 2026-09-24 04:32:42 UTC
Red Hat Product Errata RHSA-2026:71700 0 None None None 2026-09-25 06:12:54 UTC

Description OSIDB Bzimport 2026-06-24 08:02:14 UTC
In the Linux kernel, the following vulnerability has been resolved:

netfilter: nf_queue: hold bridge skb->dev while queued

br_pass_frame_up() rewrites skb->dev from the ingress port to the bridge
master before queueing bridge LOCAL_IN packets. NFQUEUE only holds
references on state.in/out and bridge physdevs, so a queued bridge
packet can retain a freed bridge master in skb->dev until reinjection.

When the verdict is reinjected later, br_netif_receive_skb() re-enters
the receive path with skb->dev still pointing at the freed bridge master,
triggering a use-after-free.

Store skb->dev in the queue entry, hold a reference on it for the queue
lifetime, and use the saved device when dropping queued packets during
NETDEV_DOWN handling.

Comment 1 Mauro Matteo Cascella 2026-06-24 17:40:14 UTC
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2026062426-CVE-2026-52912-9506@gregkh/T

Comment 6 Akiyoshi Kurita 2026-08-24 08:39:58 UTC
FYI, a working public exploit targeting RHEL 10.2 is now available.

Kconfig suggests the following may be a possible mitigation:

echo 'install bridge /bin/false' > /etc/modprobe.d/disable-bridge.conf

 This has not been fully validated as a mitigation.

Comment 7 Akiyoshi Kurita 2026-08-24 08:43:52 UTC
Correction: Comment #6 was posted here by mistake. Please disregard it.

Comment 11 Jon Orris 2026-09-24 04:32:41 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:71330 https://access.redhat.com/errata/RHSA-2026:71330

Comment 12 Jon Orris 2026-09-24 05:25:16 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:71329 https://access.redhat.com/errata/RHSA-2026:71329

Comment 13 Jon Orris 2026-09-25 06:12:54 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:71700 https://access.redhat.com/errata/RHSA-2026:71700


Note You need to log in before you can comment on or make changes to this bug.