Answer in brief
CVE-2026-72320 records a Critical severity (CVSS 9.1) vulnerability in netfilter: nft_lookup: fix catchall element handling with inverted lookups. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 9.1. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=aaa31047a6d25da0fa101da1ed544e1247949b40 <0ab8880865f9678eb6174e72c1fc4712e44c745c || >=aaa31047a6d25da0fa101da1ed544e1247949b40 <238c612357b5a25f03eacf356f95034f8551f218 || >=aaa31047a6d25da0fa101da1ed544e1247949b40 <ef0c7d4b04a0e6ad175323c24bc84e11470dd79d || >=aaa31047a6d25da0fa101da1ed544e1247949b40 <e6107a4c74b54cb33e3bce162a63048ae5a6b198 | 0ab8880865f9678eb6174e72c1fc4712e44c745c, 238c612357b5a25f03eacf356f95034f8551f218, ef0c7d4b04a0e6ad175323c24bc84e11470dd79d, e6107a4c74b54cb33e3bce162a63048ae5a6b198 |
| Linux/Linuxgeneric | 5.13 | Not reported |
Published upstream
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 15, 2026
In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_lookup: fix catchall element handling with inverted lookups nft_lookup_eval() decides whether a lookup matched (`found`) from the direct set lookup and priv->invert before falling back to the catchall element used by interval sets (e.g. nft_set_rbtree) for the open-ended default range. Since `found` is never recomputed after `ext` is replaced by the catchall lookup, inverted lookups (NFT_LOOKUP_F_INV, "!= @set") can wrongly match or wrongly skip the catchall element, producing the wrong verdict. Fold the catchall lookup into `ext` before computing `found`, matching the order already used by nft_objref_map_eval().
Quoted source text, attributed separately from HOL analysis.