netfilter: xt_policy: fix strict mode inbound policy matching
Summary
| CVE | CVE-2026-52920 |
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-06-24 08:16:21 UTC |
| Updated | 2026-06-24 08:16:21 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved:
netfilter: xt_policy: fix strict mode inbound policy matching
match_policy_in() walks sec_path entries from the last transform to the
first one, but strict policy matching needs to consume info->pol[] in
the same forward order as the rule layout.
Derive the strict-match policy position from the number of transforms
already consumed so that multi-element inbound rules are matched
consistently. |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|
| CNA |
Linux |
Linux |
affected c4b885139203d37f76662c37ae645fe8e0f4e4e5 eb323f7b82d2e2f638de0cc2a177803eb20e0707 git |
Not specified |
| CNA |
Linux |
Linux |
affected c4b885139203d37f76662c37ae645fe8e0f4e4e5 fc1c518bb1f054831ecabb32da9b8e1dff9699c6 git |
Not specified |
| CNA |
Linux |
Linux |
affected c4b885139203d37f76662c37ae645fe8e0f4e4e5 f98b7f85e04b40e28b08c461ded0cc79f14f5509 git |
Not specified |
| CNA |
Linux |
Linux |
affected c4b885139203d37f76662c37ae645fe8e0f4e4e5 82664d0f1ba25e4f9a71994954abae24c60f4067 git |
Not specified |
| CNA |
Linux |
Linux |
affected c4b885139203d37f76662c37ae645fe8e0f4e4e5 b130a6eefa02bd4d475f2f059da8bcfb3e7d18d9 git |
Not specified |
| CNA |
Linux |
Linux |
affected c4b885139203d37f76662c37ae645fe8e0f4e4e5 938867e870fb5471bb16f442aeac81326e05bf65 git |
Not specified |
| CNA |
Linux |
Linux |
affected c4b885139203d37f76662c37ae645fe8e0f4e4e5 392cc1d8408b5665215c1e9290bbf0f92339b043 git |
Not specified |
| CNA |
Linux |
Linux |
affected c4b885139203d37f76662c37ae645fe8e0f4e4e5 4b2b4d7d4e203c92db8966b163edfacb1f0e1e29 git |
Not specified |
| CNA |
Linux |
Linux |
affected 2.6.17 |
Not specified |
| CNA |
Linux |
Linux |
unaffected 2.6.17 semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 5.10.258 5.10.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 5.15.209 5.15.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.1.175 6.1.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.6.141 6.6.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.12.91 6.12.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.18.33 6.18.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.0.10 7.0.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.1 * original_commit_for_fix |
Not specified |
References
| Reference | Source | Link | Tags |
|---|
| git.kernel.org/stable/c/4b2b4d7d4e203c92db8966b163edfacb1f0e1e29 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/938867e870fb5471bb16f442aeac81326e05bf65 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/b130a6eefa02bd4d475f2f059da8bcfb3e7d18d9 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/f98b7f85e04b40e28b08c461ded0cc79f14f5509 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/eb323f7b82d2e2f638de0cc2a177803eb20e0707 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/82664d0f1ba25e4f9a71994954abae24c60f4067 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/fc1c518bb1f054831ecabb32da9b8e1dff9699c6 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/392cc1d8408b5665215c1e9290bbf0f92339b043 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.