In the Linux kernel, the following vulnerability has been resolved: netfilter: br_netfilter: do not check confirmed bit in br_nf_local_in() after confirm When send a broadcast packet to a tap devic…
High CVSS 7.5
Summary
In the Linux kernel, the following vulnerability has been resolved: netfilter: br_netfilter: do not check confirmed bit in br_nf_local_in() after confirm When send a broadcast packet to a tap device, which was added to a bridge, br_nf_local_in() is called to confirm the conntrack. If another conntrack with the same hash value is added to the hash table, which can be triggered by a normal packet to a non-bridge device, the below warning may happen. ------------[ cut here ]------------ WAR…
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
- :
Sources
- NVD DATABASE
Original Links
- https://git.kernel.org/stable/c/479a54ab92087318514c82428a87af2d7af1a576 Patch
- https://git.kernel.org/stable/c/50db11e2bbb635e38e3dd096215580d6adb41fb0 Patch
- https://git.kernel.org/stable/c/a74abcf0f09f59daeecf7a3ba9c1d690808b0afe Patch
- https://git.kernel.org/stable/c/c47ca77fee9071aa543bae592dd2a384f895c8b6 Patch
- https://git.kernel.org/stable/c/ccbad4803225eafe0175d3cb19f0d8d73b504a94 Patch
- https://git.kernel.org/stable/c/d00c8b0daf56012f69075e3377da67878c775e4c Patch
- https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html Third Party Advisory
Timeline
- nvd_ingest NVD