CVE-2026-52920
In the Linux kernel, the following vulnerability has been resolved: netfilter: xt_policy: fix strict mode inbound policy matching match_policy_in() walks sec_path entries from the last transform to the first one, but strict policy matching needs to…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.30%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
In the Linux kernel, the following vulnerability has been resolved: netfilter: xt_policy: fix strict mode inbound policy matching match_policy_in() walks sec_path entries from the last transform to the first one, but strict policy matching needs to consume info->pol[] in the same forward order as the rule layout. Derive the strict-match policy position from the number of transforms already consumed so that multi-element inbound rules are matched consistently.
- CVSS 3.1
- 8.3 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H
- EPSS
- 0.30% probability · 22th percentile
- CISA KEV
- Not listed
- Affected
- linux/linux kernel
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
References
- https://git.kernel.org/stable/c/392cc1d8408b5665215c1e9290bbf0f92339b043Patch
- https://git.kernel.org/stable/c/4b2b4d7d4e203c92db8966b163edfacb1f0e1e29Patch
- https://git.kernel.org/stable/c/82664d0f1ba25e4f9a71994954abae24c60f4067Patch
- https://git.kernel.org/stable/c/938867e870fb5471bb16f442aeac81326e05bf65Patch
- https://git.kernel.org/stable/c/b130a6eefa02bd4d475f2f059da8bcfb3e7d18d9Patch
- https://git.kernel.org/stable/c/eb323f7b82d2e2f638de0cc2a177803eb20e0707Patch
- https://git.kernel.org/stable/c/f98b7f85e04b40e28b08c461ded0cc79f14f5509Patch
- https://git.kernel.org/stable/c/fc1c518bb1f054831ecabb32da9b8e1dff9699c6Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.