CVE-2026-52920
published 2026-06-24CVE-2026-52920: In the Linux kernel, the following vulnerability has been resolved: netfilter: xt_policy: fix strict mode inbound policy matching match_policy_in() walks…
PriorityP342high8.3CVSS 3.1
AVNACLPRLUINSUCHILAH
EPSS
0.30%
21.7th percentile
In the Linux kernel, the following vulnerability has been resolved:
netfilter: xt_policy: fix strict mode inbound policy matching
match_policy_in() walks sec_path entries from the last transform to the
first one, but strict policy matching needs to consume info->pol[] in
the same forward order as the rule layout.
Derive the strict-match policy position from the number of transforms
already consumed so that multi-element inbound rules are matched
consistently.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| linux | linux | — | — |
| linux | linux | >= c4b885139203d37f76662c37ae645fe8e0f4e4e5 < eb323f7b82d2e2f638de0cc2a177803eb20e0707 | eb323f7b82d2e2f638de0cc2a177803eb20e0707 |
| linux | linux | >= c4b885139203d37f76662c37ae645fe8e0f4e4e5 < fc1c518bb1f054831ecabb32da9b8e1dff9699c6 | fc1c518bb1f054831ecabb32da9b8e1dff9699c6 |
| linux | linux | >= c4b885139203d37f76662c37ae645fe8e0f4e4e5 < f98b7f85e04b40e28b08c461ded0cc79f14f5509 | f98b7f85e04b40e28b08c461ded0cc79f14f5509 |
| linux | linux | >= c4b885139203d37f76662c37ae645fe8e0f4e4e5 < 82664d0f1ba25e4f9a71994954abae24c60f4067 | 82664d0f1ba25e4f9a71994954abae24c60f4067 |
| linux | linux | >= c4b885139203d37f76662c37ae645fe8e0f4e4e5 < b130a6eefa02bd4d475f2f059da8bcfb3e7d18d9 | b130a6eefa02bd4d475f2f059da8bcfb3e7d18d9 |
| linux | linux | >= c4b885139203d37f76662c37ae645fe8e0f4e4e5 < 938867e870fb5471bb16f442aeac81326e05bf65 | 938867e870fb5471bb16f442aeac81326e05bf65 |
| linux | linux | >= c4b885139203d37f76662c37ae645fe8e0f4e4e5 < 392cc1d8408b5665215c1e9290bbf0f92339b043 | 392cc1d8408b5665215c1e9290bbf0f92339b043 |
| linux | linux | >= c4b885139203d37f76662c37ae645fe8e0f4e4e5 < 4b2b4d7d4e203c92db8966b163edfacb1f0e1e29 | 4b2b4d7d4e203c92db8966b163edfacb1f0e1e29 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 2.6.17 < 5.10.258 | 5.10.258 |
| linux | linux_kernel | >= 5.11 < 5.15.209 | 5.15.209 |
| linux | linux_kernel | >= 5.16 < 6.1.175 | 6.1.175 |
| linux | linux_kernel | >= 6.13 < 6.18.33 | 6.18.33 |
| linux | linux_kernel | >= 6.19 < 7.0.10 | 7.0.10 |
| linux | linux_kernel | >= 6.2 < 6.6.141 | 6.6.141 |
| linux | linux_kernel | >= 6.7 < 6.12.91 | 6.12.91 |
CVSS provenance
nvdv3.18.3HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H
vendor_redhat7.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
In the Linux kernel, the following vulnerability has been resolved: netfilter: xt_policy: fix strict mode inbound policy matching match_policy_in() walks sec_path entries from the last transform to
ghsa_unreviewed·2026-06-24
CVE-2026-52920 In the Linux kernel, the following vulnerability has been resolved: netfilter: xt_policy: fix strict mode inbound policy matching match_policy_in() walks sec_path entries from the last transform to
In the Linux kernel, the following vulnerability has been resolved:
netfilter: xt_policy: fix strict mode inbound policy matching
match_policy_in() walks sec_path entries from the last transform to the
first one, but strict policy matching needs to consume info->pol[] in
the same forward order as the rule layout.
Derive the strict-match policy position from the number of transforms
already consumed so that multi-element inbound rules are matched
consistently.
Red Hat
kernel: netfilter: xt_policy: fix strict mode inbound policy matching
vendor_redhat·2026-06-24·CVSS 7.0
CVE-2026-52920 [MEDIUM] CWE-551 kernel: netfilter: xt_policy: fix strict mode inbound policy matching
kernel: netfilter: xt_policy: fix strict mode inbound policy matching
A flaw was found in the Linux kernel's netfilter component, which is responsible for network packet filtering. This vulnerability, located in the `xt_policy` module, involves an error in how strict inbound network policies are matched. This could allow an attacker to bypass established security rules, potentially leading to unauthorized network access or unintended exposure of services. The flaw could compromise the effectiveness of network traffic control.
Package: kernel (Red Hat Enterprise Linux 10) - Affected
Package: kernel (Red Hat Enterprise Linux 6) - Out of support scope
Package: kernel (Red Hat Enterprise Linux 7) - Affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Affected
Package: kernel (Red H
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/392cc1d8408b5665215c1e9290bbf0f92339b043https://git.kernel.org/stable/c/4b2b4d7d4e203c92db8966b163edfacb1f0e1e29https://git.kernel.org/stable/c/82664d0f1ba25e4f9a71994954abae24c60f4067https://git.kernel.org/stable/c/938867e870fb5471bb16f442aeac81326e05bf65https://git.kernel.org/stable/c/b130a6eefa02bd4d475f2f059da8bcfb3e7d18d9https://git.kernel.org/stable/c/eb323f7b82d2e2f638de0cc2a177803eb20e0707https://git.kernel.org/stable/c/f98b7f85e04b40e28b08c461ded0cc79f14f5509https://git.kernel.org/stable/c/fc1c518bb1f054831ecabb32da9b8e1dff9699c6
2026-06-24
Published