All of lore.kernel.org
 help / color / mirror / Atom feed
* CVE-2026-72255: netfilter: nf_queue: pin bridge device while NFQUEUE holds fake dst
@ 2026-08-15  6:05 Greg Kroah-Hartman
  0 siblings, 0 replies; only message in thread
From: Greg Kroah-Hartman @ 2026-08-15  6:05 UTC (permalink / raw)
  To: linux-cve-announce; +Cc: Greg Kroah-Hartman

From: Greg Kroah-Hartman <gregkh@kernel.org>

Description
===========

In the Linux kernel, the following vulnerability has been resolved:

netfilter: nf_queue: pin bridge device while NFQUEUE holds fake dst

The br_netfilter fake rtable is embedded in struct net_bridge and is
attached to bridged packets with skb_dst_set_noref(). If such a packet is
queued to NFQUEUE, __nf_queue() upgrades that fake dst with
skb_dst_force().

At that point the queued skb can hold a real dst reference after bridge
teardown has started. The problem is not that every bridged packet needs
its own dst reference. The problem is that NFQUEUE can keep the bridge
private fake dst alive after unregister begins.

Fix this by keeping the bridge fake dst model unchanged and pinning the
bridge master device only while the packet sits in NFQUEUE. Record the
bridge device in nf_queue_entry when the queued skb carries a bridge fake
dst, take a device reference for the queue lifetime, and drop it when the
queue entry is freed.

Also make sure queued entries are reaped when that bridge device goes
down, and drop the redundant nf_bridge_info_exists() test from the fake
dst detection.

This keeps netdev_priv(br->dev) alive until verdict completion, so the
embedded fake rtable and its metrics backing storage cannot be freed out
from under dst_release(). It also avoids the constant refcount bump and
avoids using ipv4-specific dst helpers for IPv6 bridge traffic.

The Linux kernel CVE team has assigned CVE-2026-72255 to this issue.


Affected and fixed versions
===========================

	Issue introduced in 3.18 with commit 34666d467cbf1e2e3c7bb15a63eccfb582cdd71f and fixed in 6.1.178 with commit 430521af7fe8a9c08f5a2554224a35f11f51d99e
	Issue introduced in 3.18 with commit 34666d467cbf1e2e3c7bb15a63eccfb582cdd71f and fixed in 6.6.145 with commit 3f03a2d225c668283110ad5f9ff159ba4591e2c7
	Issue introduced in 3.18 with commit 34666d467cbf1e2e3c7bb15a63eccfb582cdd71f and fixed in 6.12.97 with commit 01ace27af47801dd7f6b839e782b62863af979cc
	Issue introduced in 3.18 with commit 34666d467cbf1e2e3c7bb15a63eccfb582cdd71f and fixed in 6.18.40 with commit 0ca505346c5e2905ab7b5313af801fcf38f594a8
	Issue introduced in 3.18 with commit 34666d467cbf1e2e3c7bb15a63eccfb582cdd71f and fixed in 7.1.5 with commit 47b3af24de5fbed4bf2952de0f5294ef1a338a26
	Issue introduced in 3.18 with commit 34666d467cbf1e2e3c7bb15a63eccfb582cdd71f and fixed in 7.2-rc1 with commit c9c9b37f8c5505224e8d206184df3bb668ee00cf

Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.

Unaffected versions might change over time as fixes are backported to
older supported kernel versions.  The official CVE entry at
	https://cve.org/CVERecord/?id=CVE-2026-72255
will be updated if fixes are backported, please check that for the most
up to date information about this issue.


Affected files
==============

The file(s) affected by this issue are:
	include/net/netfilter/nf_queue.h
	net/netfilter/nf_queue.c
	net/netfilter/nfnetlink_queue.c


Mitigation
==========

The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes.  Individual
changes are never tested alone, but rather are part of a larger kernel
release.  Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all.  If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
	https://git.kernel.org/stable/c/430521af7fe8a9c08f5a2554224a35f11f51d99e
	https://git.kernel.org/stable/c/3f03a2d225c668283110ad5f9ff159ba4591e2c7
	https://git.kernel.org/stable/c/01ace27af47801dd7f6b839e782b62863af979cc
	https://git.kernel.org/stable/c/0ca505346c5e2905ab7b5313af801fcf38f594a8
	https://git.kernel.org/stable/c/47b3af24de5fbed4bf2952de0f5294ef1a338a26
	https://git.kernel.org/stable/c/c9c9b37f8c5505224e8d206184df3bb668ee00cf

^ permalink raw reply	[flat|nested] only message in thread

only message in thread, other threads:[~2026-08-15  6:20 UTC | newest]

Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-15  6:05 CVE-2026-72255: netfilter: nf_queue: pin bridge device while NFQUEUE holds fake dst Greg Kroah-Hartman

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.