All of lore.kernel.org
 help / color / mirror / Atom feed
* CVE-2026-72433: netfilter: nft_meta_bridge: fix NFT_META_BRI_IIFPVID stack leak
@ 2026-08-15  6:08 Greg Kroah-Hartman
  0 siblings, 0 replies; only message in thread
From: Greg Kroah-Hartman @ 2026-08-15  6:08 UTC (permalink / raw)
  To: linux-cve-announce; +Cc: Greg Kroah-Hartman

From: Greg Kroah-Hartman <gregkh@kernel.org>

Description
===========

In the Linux kernel, the following vulnerability has been resolved:

netfilter: nft_meta_bridge: fix NFT_META_BRI_IIFPVID stack leak

This needs to test for nonzero retval.

The Linux kernel CVE team has assigned CVE-2026-72433 to this issue.


Affected and fixed versions
===========================

	Issue introduced in 5.3 with commit c54c7c685494fc0f1662091d4d0c4fc26e810471 and fixed in 5.10.261 with commit c37a39b963034cc2d141baf46017614cb1fc275f
	Issue introduced in 5.3 with commit c54c7c685494fc0f1662091d4d0c4fc26e810471 and fixed in 5.15.212 with commit a853c3769b73ceb2d2b735aff621d1d51fe0553d
	Issue introduced in 5.3 with commit c54c7c685494fc0f1662091d4d0c4fc26e810471 and fixed in 6.1.178 with commit b1b0b9efe641afa5c2d4ba2ec77aed7b6f4bc398
	Issue introduced in 5.3 with commit c54c7c685494fc0f1662091d4d0c4fc26e810471 and fixed in 6.6.145 with commit f73b7de5338fcca7f63ca88597a050c119501531
	Issue introduced in 5.3 with commit c54c7c685494fc0f1662091d4d0c4fc26e810471 and fixed in 6.12.97 with commit 92c9682b36f0c8f7a1f14d4558b72793f62e90a1
	Issue introduced in 5.3 with commit c54c7c685494fc0f1662091d4d0c4fc26e810471 and fixed in 6.18.40 with commit 7e23965d44f06ed93fb5362fb1e321b769eecc3b
	Issue introduced in 5.3 with commit c54c7c685494fc0f1662091d4d0c4fc26e810471 and fixed in 7.1.5 with commit 4dce8bf588a89bef99b446136d15685a837e7acf
	Issue introduced in 5.3 with commit c54c7c685494fc0f1662091d4d0c4fc26e810471 and fixed in 7.2-rc1 with commit 27dd2997746d54ebc079bb13161cc1bdd401d4a6

Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.

Unaffected versions might change over time as fixes are backported to
older supported kernel versions.  The official CVE entry at
	https://cve.org/CVERecord/?id=CVE-2026-72433
will be updated if fixes are backported, please check that for the most
up to date information about this issue.


Affected files
==============

The file(s) affected by this issue are:
	net/bridge/netfilter/nft_meta_bridge.c


Mitigation
==========

The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes.  Individual
changes are never tested alone, but rather are part of a larger kernel
release.  Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all.  If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
	https://git.kernel.org/stable/c/c37a39b963034cc2d141baf46017614cb1fc275f
	https://git.kernel.org/stable/c/a853c3769b73ceb2d2b735aff621d1d51fe0553d
	https://git.kernel.org/stable/c/b1b0b9efe641afa5c2d4ba2ec77aed7b6f4bc398
	https://git.kernel.org/stable/c/f73b7de5338fcca7f63ca88597a050c119501531
	https://git.kernel.org/stable/c/92c9682b36f0c8f7a1f14d4558b72793f62e90a1
	https://git.kernel.org/stable/c/7e23965d44f06ed93fb5362fb1e321b769eecc3b
	https://git.kernel.org/stable/c/4dce8bf588a89bef99b446136d15685a837e7acf
	https://git.kernel.org/stable/c/27dd2997746d54ebc079bb13161cc1bdd401d4a6

^ permalink raw reply	[flat|nested] only message in thread

only message in thread, other threads:[~2026-08-15  6:27 UTC | newest]

Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-15  6:08 CVE-2026-72433: netfilter: nft_meta_bridge: fix NFT_META_BRI_IIFPVID stack leak Greg Kroah-Hartman

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.