PT-2026-86703 · Azure Linux · Kernel
Published
2026-08-28
·
Updated
2026-08-28
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
netfilter: flowtable: avoid num encaps underflow on bridge VLAN untag
The DEV PATH BR VLAN UNTAG case post-decrements info->num encaps
inside WARN ON ONCE(). num encaps is u8, so if it's already 0 the
decrement still happens and wraps it to 255. The break only leaves
the inner switch -- a later path entry can set info->indev back to
a real device, and we end up returning with num encaps == 255.
nft dev forward path() then walks info.encap[] (size 2) up to
num encaps, which means an OOB stack read and a bogus count copied
into the route descriptor.
Should only happen on a malformed bridge path stack, hence the WARN,
but worth handling sanely. Move the decrement out of the WARN.
[ While at this, remove the WARN ON ONCE since this can only happen
with a buggy bridge path stack --pablo ].
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Kernel