{"id":"CVE-2026-72320","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-72320","summary":"netfilter: nft_lookup: fix catchall element handling with inverted lookups","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nft_lookup: fix catchall element handling with inverted lookups\n\nnft_lookup_eval() decides whether a lookup matched (`found`) from the\ndirect set lookup and priv->invert before falling back to the\ncatchall element used by interval sets (e.g. nft_set_rbtree) for the\nopen-ended default range. Since `found` is never recomputed after\n`ext` is replaced by the catchall lookup, inverted lookups\n(NFT_LOOKUP_F_INV, \"!= @set\") can wrongly match or wrongly skip the\ncatchall element, producing the wrong verdict. Fold the catchall\nlookup into `ext` before computing `found`, matching the order\nalready used by nft_objref_map_eval().","published":"2026-08-15T05:55:32.939Z","modified":"2026-08-16T03:48:33.035270847Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Linux","name":"Kernel","fixedVersion":"6.12.97"}],"fix":null,"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/0ab8880865f9678eb6174e72c1fc4712e44c745c"},{"type":"WEB","url":"https://git.kernel.org/stable/c/238c612357b5a25f03eacf356f95034f8551f218"},{"type":"WEB","url":"https://git.kernel.org/stable/c/e6107a4c74b54cb33e3bce162a63048ae5a6b198"},{"type":"WEB","url":"https://git.kernel.org/stable/c/ef0c7d4b04a0e6ad175323c24bc84e11470dd79d"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72320.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-72320"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-16T03:48:33.035270847Z"}}