CVE 8.3 HIGH

netfilter: xt_policy: fix strict mode inbound policy matching_CVE-2026-52920

8.3 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H

Description

In the Linux kernel, the following vulnerability has been resolved:

netfilter: xt_policy: fix strict mode inbound policy matching

match_policy_in() walks sec_path entries from the last transform to the
first one, but strict policy matching needs to consume info->pol[] in
the same forward order as the rule layout.

Derive the strict-match policy position from the number of transforms
already consumed so that multi-element inbound rules are matched
consistently.

Basic Information

ID CVE-2026-52920
Source Linux
Published Jun 24, 2026 at 07:14
Modified Jun 28, 2026 at 06:36

Affected Product

Vendor Linux
Product Linux
Version c4b885139203d37f76662c37ae645fe8e0f4e4e5
Affected Versions Linux Linux c4b885139203d37f76662c37ae645fe8e0f4e4e5
Linux Linux c4b885139203d37f76662c37ae645fe8e0f4e4e5
Linux Linux c4b885139203d37f76662c37ae645fe8e0f4e4e5
Linux Linux c4b885139203d37f76662c37ae645fe8e0f4e4e5
Linux Linux c4b885139203d37f76662c37ae645fe8e0f4e4e5
Linux Linux c4b885139203d37f76662c37ae645fe8e0f4e4e5
Linux Linux c4b885139203d37f76662c37ae645fe8e0f4e4e5
Linux Linux c4b885139203d37f76662c37ae645fe8e0f4e4e5
Linux Linux 2.6.17

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.