Executive brief
The Linux kernel's netfilter flow table component handles network packet routing and filtering. A flaw in processing bridge VLAN untag operations causes an integer underflow that wraps an 8-bit encapsulation counter to 255, leading to out-of-bounds memory reads on the kernel stack. An attacker with the ability to construct malformed network bridge configurations could trigger this vulnerability to read sensitive kernel memory or cause a denial of service.
Technical details
The vulnerability is an integer underflow in the DEV_PATH_BR_VLAN_UNTAG case of the nft_dev_path_info() function in net/netfilter/nf_flow_table_path.c. The num_encaps field is an unsigned 8-bit integer that is decremented inside a WARN_ON_ONCE() macro; if num_encaps is already 0, the post-decrement still occurs and wraps the value to 255. This allows subsequent code in nft_dev_forward_path() to iterate over info.encap[] (a 2-element array) up to index 255, resulting in an out-of-bounds stack read. The vulnerability occurs only with malformed bridge path stacks and requires no special privileges or network access beyond the ability to configure bridge VLAN paths locally. The fix moves the decrement outside the WARN macro and adds a bounds check before decrementing.
Affected products
- Linux Linux kernel affected versions prior to fix commit e052f920773b73be49eb4d8702a9f85de7464363 (introduced in e990cef6516d, affecting 5.x through 6.x series)
Timeline
- 2026-08-28: disclosed: Published on NVD
- 2026-06-07: patched: Fix commit e052f920773b73be49eb4d8702a9f85de7464363 accepted by Pablo Neira Ayuso
- 2026-07-24: patched: Backported to stable kernels via commit 2f55fa28011c97d6495d5787808db10a8c2d690d