KernelScan.io

CRITICAL Introduced in 5.13

netfilter Catchall Bypass

CVE-2026-72320

CVSS 9.1 / 10.0 NVD

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

KernelScan AI5.3MEDIUM

01

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_lookup: fix catchall element handling with inverted lookups nft_lookup_eval() decides whether a lookup matched (`found`) from the direct set lookup and priv->invert before falling back to the catchall element used by interval sets (e.g. nft_set_rbtree) for the open-ended default range. Since `found` is never recomputed after `ext` is replaced by the catchall lookup, inverted lookups (NFT_LOOKUP_F_INV, "!= @set") can wrongly match or wrongly skip the catchall element, producing the wrong verdict. Fold the catchall lookup into `ext` before computing `found`, matching the order already used by nft_objref_map_eval().

02

Engine v0.6.0

Risk summary

A logic error in nftables lookup evaluation causes inverted lookups on interval sets with catchall elements to produce incorrect firewall verdicts, potentially accepting packets that should be dropped or vice versa. Network attackers can trigger this by sending packets through affected rules without any privileges. Systems using nftables with inverted lookups and catchall elements are at risk of firewall policy bypass or selective traffic disruption.

Affectednet/netfilter/nft_lookup.c (netfilter)

Vulnerability analysis

The nftables firewall can compute the wrong decision when a rule checks whether a packet field is not in a set, and that set uses a catchall element for its default range. The fallback to the catchall happens after the negation has already been applied, so the rule may accept traffic that should be blocked or block traffic that should be allowed. The fix reorders the evaluation so the catchall is considered before the final match decision, ensuring the negation applies to the complete result. Any remote attacker can trigger the wrong verdict by sending packets through an misruled firewall; no privileges or local access are required.

03

BranchIntroducedFixed inPatch commit
6.125.136.12.970ab8880865f9
6.185.136.18.40238c612357b5
mainline5.137.2-rc3e6107a4c74b5
7.15.137.1.5ef0c7d4b04a0