Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3446 articles · 168099 vulns · 36/41 feeds (7d)
← Back to list
7.8
CVE-2026-52912EXPLOITEDPATCHED
linux · linux kernel

netfilter: nf_queue: hold bridge skb->dev while queued

Description

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_queue: hold bridge skb->dev while queued br_pass_frame_up() rewrites skb->dev from the ingress port to the bridge master before queueing bridge LOCAL_IN packets. NFQUEUE only holds references on state.in/out and bridge physdevs, so a queued bridge packet can retain a freed bridge master in skb->dev until reinjection. When the verdict is reinjected later, br_netif_receive_skb() re-enters the receive path with skb->dev still pointing at the freed bridge master, triggering a use-after-free. Store skb->dev in the queue entry, hold a reference on it for the queue lifetime, and use the saved device when dropping queued packets during NETDEV_DOWN handling.

Affected Products

VendorProductVersions
linuxlinux kernelac28634456867b23b95faccba7997a62ec430603, ac28634456867b23b95faccba7997a62ec430603, ac28634456867b23b95faccba7997a62ec430603, ac28634456867b23b95faccba7997a62ec430603, ac28634456867b23b95faccba7997a62ec430603, ac28634456867b23b95faccba7997a62ec430603, ac28634456867b23b95faccba7997a62ec430603, ac28634456867b23b95faccba7997a62ec430603, 4.7

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
linuxlinuxmitre_affected90%
open sourceopen source linux kernelcert_advisory90%

References

  • https://git.kernel.org/stable/c/950d809f154dca04e5fbe5d3c8b9c5e44769cd57
  • https://git.kernel.org/stable/c/a698ac8ab2561cf575d2d9f34095032651dd952e
  • https://git.kernel.org/stable/c/19924bdd8a45ebc72a7b84c57fd63057d1dc75ac
  • https://git.kernel.org/stable/c/1e5e20031c5eee8d2e490a90ff4d6a2feecfc3be
  • https://git.kernel.org/stable/c/3823c27099cfe2482299065814adbaa771be9644
  • https://git.kernel.org/stable/c/15d464265120ab9818bd673af301deee09bedab2
  • https://git.kernel.org/stable/c/3fb0f5c0f64162a8c3f25616a4f1e340b921737f
  • https://git.kernel.org/stable/c/e196115ec330a18de415bdb9f5071aa9f08e53ce

Related News (4 articles)

Tier A
Microsoft MSRC4h ago
CVE-2026-52912 netfilter: nf_queue: hold bridge skb->dev while queued
→ No new info (linked only)
Tier B
BSI Advisories4d ago
[NEU] [hoch] Linux Kernel: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
VulDB4d ago
CVE-2026-52912 | Linux Kernel up to 7.0.10 netfilter state.in br_pass_frame_up dev use after free
→ No new info (linked only)
Tier C
Linux Kernel CVEs4d ago
CVE-2026-52912: netfilter: nf_queue: hold bridge skb->dev while queued
→ No new info (linked only)
CVSS 3.17.8 HIGH
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
950d809f154dca04e5fbe5d3c8b9c5e44769cd57a698ac8ab2561cf575d2d9f34095032651dd952e19924bdd8a45ebc72a7b84c57fd63057d1dc75ac1e5e20031c5eee8d2e490a90ff4d6a2feecfc3be3823c27099cfe2482299065814adbaa771be964415d464265120ab9818bd673af301deee09bedab23fb0f5c0f64162a8c3f25616a4f1e340b921737fe196115ec330a18de415bdb9f5071aa9f08e53ce05.10.2595.15.2096.1.1756.6.1426.12.926.18.347.0.117.1
PublishedJun 24, 2026
Last enriched4d agov3
Trending Score65
Source articles4
Independent4
Info Completeness7/14
Missing: cvss, epss, cwe, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-31431EXPKEV
crypto: algif_aead - Revert to operating out-of-place
Trending: 109
HIGHCVE-2026-43284EXPKEV
xfrm: esp: avoid in-place decrypt on shared skb frags
Trending: 105
HIGHCVE-2026-43500EXPKEV
rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present
Trending: 99
HIGHCVE-2026-46243EXP
smb: client: reject userspace cifs.spnego descriptions
Trending: 85
HIGHCVE-2026-46333EXP
ptrace: slightly saner 'get_dumpable()' logic
Trending: 69

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jun 24, 2026
Discovered by ZDM
Jun 24, 2026
Updated: affectedVersions
Jun 24, 2026
Updated: description, affectedVersions, severity, activelyExploited
Jun 24, 2026
Actively Exploited
Jun 28, 2026
Patch Available
Jun 28, 2026

Version History

v3
Last enriched 4d ago
v3Tier C4d ago

Updated severity to CRITICAL, added affected version 7.0.10, and corrected exploit availability to false.

descriptionaffectedVersionsseverityactivelyExploited
via VulDB
v2Tier C4d ago

Updated description with more technical detail, added affected version 4.7, and changed severity to HIGH.

affectedVersions
via Linux Kernel CVEs
v14d ago

Initial creation