| Summary | In the Linux kernel, the following vulnerability has been resolved: netfilter: revalidate bridge ports ebt_redirect_tg() dereferences br_port_get_rcu() return without a A mere NULL check isn't sufficient, however. As sashiko review If this happens, we must drop the packet, there is no way for us to Switch to _upper API, we don't need the bridge port structure. Both nfnetlink_log and nfnetlink_queue use CONFIG_BRIDGE_NETFILTER Fixes tag is a common ancestor, this was always broken. |
|---|---|
| Publication Date | June 25, 2026, 6:16 p.m. |
| Registration Date | June 27, 2026, 4:27 a.m. |
| Last Update | June 25, 2026, 6:16 p.m. |