Description
In the Linux kernel, the following vulnerability has been resolved:

netfilter: nft_compat: ebtables emulation must reject non-bridge targets

xtables targets return netfilter verdicts: NF_ACCEPT, NF_DROP, and so
on. ebtables targets return incompatible verdicts: EBT_ACCEPT,
EBT_DROP, ... We cannot allow fallback to NFPROTO_UNSPEC.

ebtables doesn't permit this since
11ff7288beb2 ("netfilter: ebtables: reject non-bridge targets")
but that commit missed the nft_compat layer.
Published: 2026-08-15
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability arises in the Linux kernel’s netfilter nft_compat layer, where ebtables emulation mistakenly permits non‑bridge targets to be accepted. The result is that firewall rules can incorrectly allow traffic that should be blocked, effectively bypassing ebtables’ filtering logic. The underlying weakness is improper validation of target types, a common input‑validation or access‑control failure. Consequently, an attacker could manipulate network traffic to gain unauthorized connectivity or evade filters, depending on the context of the rule set.

Affected Systems

The affected product is the Linux kernel. No specific kernel versions are listed in the CNA data, so any kernel build that includes the nft_compat layer without the latest ebtables target rejection patch is potentially vulnerable. Administrators should verify the kernel version against vendor release notes for the commit that introduced the fix.

Risk and Exploitability

The CVSS and EPSS metrics are not publicly available, and the vulnerability is not listed in CISA’s KEV catalog, indicating no confirmed exploitation is known. The likely attack vector involves a local user with rights to add or modify netfilter rules; an attacker could craft a rule that utilizes a non‑bridge target, causing the kernel to incorrectly apply a drop or accept verdict. Because the flaw resides in kernel‑space logic, exploitation would require local or privileged access, but in multi‑tenant or high‑privilege scenarios this could lead to widespread network bypass.

Generated by OpenCVE AI on August 15, 2026 at 11:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update to a kernel version that includes the commit fixing ebtables target rejection (e.g., the latest stable release after 33e1875d6b5b552a2e5652b40074c604199354ee).
  • Restrict the ability to add or modify netfilter rules to trusted users or groups, reducing the risk of accidental misuse.
  • If a kernel update cannot be applied immediately, manually configure ebtables rules to reject any non‑bridge targets using the EBT_REJECT target or by disabling ebtables emulation in nft_compat.

Generated by OpenCVE AI on August 15, 2026 at 11:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 15 Aug 2026 11:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
CWE-284

Sat, 15 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_compat: ebtables emulation must reject non-bridge targets xtables targets return netfilter verdicts: NF_ACCEPT, NF_DROP, and so on. ebtables targets return incompatible verdicts: EBT_ACCEPT, EBT_DROP, ... We cannot allow fallback to NFPROTO_UNSPEC. ebtables doesn't permit this since 11ff7288beb2 ("netfilter: ebtables: reject non-bridge targets") but that commit missed the nft_compat layer.
Title netfilter: nft_compat: ebtables emulation must reject non-bridge targets
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-15T05:56:36.886Z

Reserved: 2026-08-09T03:40:39.927Z

Link: CVE-2026-72416

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-15T06:22:15.223

Modified: 2026-08-15T06:22:15.223

Link: CVE-2026-72416

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-15T11:15:03Z

Weaknesses
  • CWE-20

    Improper Input Validation

  • CWE-284

    Improper Access Control