9.1

CVE-2026-72320

netfilter: nft_lookup: fix catchall element handling with inverted lookups

In the Linux kernel, the following vulnerability has been resolved:

netfilter: nft_lookup: fix catchall element handling with inverted lookups

nft_lookup_eval() decides whether a lookup matched (`found`) from the
direct set lookup and priv->invert before falling back to the
catchall element used by interval sets (e.g. nft_set_rbtree) for the
open-ended default range. Since `found` is never recomputed after
`ext` is replaced by the catchall lookup, inverted lookups
(NFT_LOOKUP_F_INV, "!= @set") can wrongly match or wrongly skip the
catchall element, producing the wrong verdict. Fold the catchall
lookup into `ext` before computing `found`, matching the order
already used by nft_objref_map_eval().
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version aaa31047a6d25da0fa101da1ed544e1247949b40
Version < 0ab8880865f9678eb6174e72c1fc4712e44c745c
Status affected
Version aaa31047a6d25da0fa101da1ed544e1247949b40
Version < 238c612357b5a25f03eacf356f95034f8551f218
Status affected
Version aaa31047a6d25da0fa101da1ed544e1247949b40
Version < ef0c7d4b04a0e6ad175323c24bc84e11470dd79d
Status affected
Version aaa31047a6d25da0fa101da1ed544e1247949b40
Version < e6107a4c74b54cb33e3bce162a63048ae5a6b198
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 5.13
Status affected
Version 0
Version < 5.13
Status unaffected
Version <= 6.12.*
Version 6.12.97
Status unaffected
Version <= 6.18.*
Version 6.18.40
Status unaffected
Version <= 7.1.*
Version 7.1.5
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.52% 0.419
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 9.1 3.9 5.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/0ab8880865f9678eb6174e72c1fc4712e44c745c
https://git.kernel.org/stable/c/238c612357b5a25f03eacf356f95034f8551f218
https://git.kernel.org/stable/c/ef0c7d4b04a0e6ad175323c24bc84e11470dd79d
https://git.kernel.org/stable/c/e6107a4c74b54cb33e3bce162a63048ae5a6b198