8.3
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H
Description
In the Linux kernel, the following vulnerability has been resolved:
netfilter: xt_policy: fix strict mode inbound policy matching
match_policy_in() walks sec_path entries from the last transform to the
first one, but strict policy matching needs to consume info->pol[] in
the same forward order as the rule layout.
Derive the strict-match policy position from the number of transforms
already consumed so that multi-element inbound rules are matched
consistently.
netfilter: xt_policy: fix strict mode inbound policy matching
match_policy_in() walks sec_path entries from the last transform to the
first one, but strict policy matching needs to consume info->pol[] in
the same forward order as the rule layout.
Derive the strict-match policy position from the number of transforms
already consumed so that multi-element inbound rules are matched
consistently.
Basic Information
ID
CVE-2026-52920
Source
Linux
Published
Jun 24, 2026 at 07:14
Modified
Jun 28, 2026 at 06:36
Affected Product
Vendor
Linux
Product
Linux
Version
c4b885139203d37f76662c37ae645fe8e0f4e4e5
Affected Versions
Linux Linux c4b885139203d37f76662c37ae645fe8e0f4e4e5
Linux Linux c4b885139203d37f76662c37ae645fe8e0f4e4e5
Linux Linux c4b885139203d37f76662c37ae645fe8e0f4e4e5
Linux Linux c4b885139203d37f76662c37ae645fe8e0f4e4e5
Linux Linux c4b885139203d37f76662c37ae645fe8e0f4e4e5
Linux Linux c4b885139203d37f76662c37ae645fe8e0f4e4e5
Linux Linux c4b885139203d37f76662c37ae645fe8e0f4e4e5
Linux Linux c4b885139203d37f76662c37ae645fe8e0f4e4e5
Linux Linux 2.6.17
Linux Linux c4b885139203d37f76662c37ae645fe8e0f4e4e5
Linux Linux c4b885139203d37f76662c37ae645fe8e0f4e4e5
Linux Linux c4b885139203d37f76662c37ae645fe8e0f4e4e5
Linux Linux c4b885139203d37f76662c37ae645fe8e0f4e4e5
Linux Linux c4b885139203d37f76662c37ae645fe8e0f4e4e5
Linux Linux c4b885139203d37f76662c37ae645fe8e0f4e4e5
Linux Linux c4b885139203d37f76662c37ae645fe8e0f4e4e5
Linux Linux 2.6.17
References
- git.kernel.org /stable/c/eb323f7b82d2e2f638de0cc2a177803eb20e0707
- git.kernel.org /stable/c/fc1c518bb1f054831ecabb32da9b8e1dff9699c6
- git.kernel.org /stable/c/f98b7f85e04b40e28b08c461ded0cc79f14f5509
- git.kernel.org /stable/c/82664d0f1ba25e4f9a71994954abae24c60f4067
- git.kernel.org /stable/c/b130a6eefa02bd4d475f2f059da8bcfb3e7d18d9
- git.kernel.org /stable/c/938867e870fb5471bb16f442aeac81326e05bf65
- git.kernel.org /stable/c/392cc1d8408b5665215c1e9290bbf0f92339b043
- git.kernel.org /stable/c/4b2b4d7d4e203c92db8966b163edfacb1f0e1e29