CVE-2026-72416

Source
https://cve.org/CVERecord?id=CVE-2026-72416
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72416.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-72416
Downstream
Published
2026-08-15T05:56:36.886Z
Modified
2026-08-18T03:56:43.229916586Z
Severity
  • 7.3 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H CVSS Calculator
Summary
netfilter: nft_compat: ebtables emulation must reject non-bridge targets
Details

In the Linux kernel, the following vulnerability has been resolved:

netfilter: nft_compat: ebtables emulation must reject non-bridge targets

xtables targets return netfilter verdicts: NFACCEPT, NFDROP, and so on. ebtables targets return incompatible verdicts: EBTACCEPT, EBTDROP, ... We cannot allow fallback to NFPROTO_UNSPEC.

ebtables doesn't permit this since 11ff7288beb2 ("netfilter: ebtables: reject non-bridge targets") but that commit missed the nft_compat layer.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72416.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
0ca743a5599199152a31a7146b83213c786c2eb2
Fixed
efc17b9240d821c424bc5191a5c6e9384a06293e
Fixed
b3f7a84540a0d014ec42343ff5909657c1bd1994
Fixed
33e1875d6b5b552a2e5652b40074c604199354ee
Fixed
c129b0185e707dce405968e21afccd5728b2ce63
Fixed
9dbba7e694ec045f21ede2f892fb42b81b4e1692

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72416.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.13.0
Fixed
6.6.145
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.97
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.40
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72416.json"