CRITICAL Introduced in 5.13
netfilter Catchall Bypass
CVE-2026-72320
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
KernelScan AI5.3MEDIUM
01Description
In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_lookup: fix catchall element handling with inverted lookups nft_lookup_eval() decides whether a lookup matched (`found`) from the direct set lookup and priv->invert before falling back to the catchall element used by interval sets (e.g. nft_set_rbtree) for the open-ended default range. Since `found` is never recomputed after `ext` is replaced by the catchall lookup, inverted lookups (NFT_LOOKUP_F_INV, "!= @set") can wrongly match or wrongly skip the catchall element, producing the wrong verdict. Fold the catchall lookup into `ext` before computing `found`, matching the order already used by nft_objref_map_eval().
02KernelScan AI Analysis
Risk summary
A logic error in nftables lookup evaluation causes inverted lookups on interval sets with catchall elements to produce incorrect firewall verdicts, potentially accepting packets that should be dropped or vice versa. Network attackers can trigger this by sending packets through affected rules without any privileges. Systems using nftables with inverted lookups and catchall elements are at risk of firewall policy bypass or selective traffic disruption.
Vulnerability analysis
The nftables firewall can compute the wrong decision when a rule checks whether a packet field is not in a set, and that set uses a catchall element for its default range. The fallback to the catchall happens after the negation has already been applied, so the rule may accept traffic that should be blocked or block traffic that should be allowed. The fix reorders the evaluation so the catchall is considered before the final match decision, ensuring the negation applies to the complete result. Any remote attacker can trigger the wrong verdict by sending packets through an misruled firewall; no privileges or local access are required.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| 6.12 | 5.13 | 6.12.97 | 0ab8880865f9 |
| 6.18 | 5.13 | 6.18.40 | 238c612357b5 |
| mainline | 5.13 | 7.2-rc3 | e6107a4c74b5 |
| 7.1 | 5.13 | 7.1.5 | ef0c7d4b04a0 |