{"id":"CVE-2026-72320","summary":"netfilter: nft_lookup: fix catchall element handling with inverted lookups","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nft_lookup: fix catchall element handling with inverted lookups\n\nnft_lookup_eval() decides whether a lookup matched (`found`) from the\ndirect set lookup and priv-\u003einvert before falling back to the\ncatchall element used by interval sets (e.g. nft_set_rbtree) for the\nopen-ended default range. Since `found` is never recomputed after\n`ext` is replaced by the catchall lookup, inverted lookups\n(NFT_LOOKUP_F_INV, \"!= @set\") can wrongly match or wrongly skip the\ncatchall element, producing the wrong verdict. Fold the catchall\nlookup into `ext` before computing `found`, matching the order\nalready used by nft_objref_map_eval().","modified":"2026-08-18T03:56:41.428157211Z","published":"2026-08-15T05:55:32.939Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72320.json","cna_assigner":"Linux"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/0ab8880865f9678eb6174e72c1fc4712e44c745c"},{"type":"WEB","url":"https://git.kernel.org/stable/c/238c612357b5a25f03eacf356f95034f8551f218"},{"type":"WEB","url":"https://git.kernel.org/stable/c/e6107a4c74b54cb33e3bce162a63048ae5a6b198"},{"type":"WEB","url":"https://git.kernel.org/stable/c/ef0c7d4b04a0e6ad175323c24bc84e11470dd79d"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72320.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-72320"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"aaa31047a6d25da0fa101da1ed544e1247949b40"},{"fixed":"0ab8880865f9678eb6174e72c1fc4712e44c745c"},{"fixed":"238c612357b5a25f03eacf356f95034f8551f218"},{"fixed":"ef0c7d4b04a0e6ad175323c24bc84e11470dd79d"},{"fixed":"e6107a4c74b54cb33e3bce162a63048ae5a6b198"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72320.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.13.0"},{"fixed":"6.12.97"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.40"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.1.5"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72320.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"}]}