SB20260815307 - Always-Incorrect Control Flow Implementation in Linux kernel net



SB20260815307 - Always-Incorrect Control Flow Implementation in Linux kernel net

Published: August 15, 2026

Security Bulletin ID SB20260815307
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Always-Incorrect Control Flow Implementation (CVE-ID: CVE-2026-72421)

CWE-ID: CWE-670 - Always-Incorrect Control Flow Implementation

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to bypass intended unreachable routing behavior.

The vulnerability exists due to improper control flow in fib_lookup() in the IPv4 FIB lookup logic when performing route lookups with CONFIG_IP_MULTIPLE_TABLES enabled and no rule added. A local user can configure routes that trigger lookup of the merged local/main table followed by the default table to bypass intended unreachable routing behavior.

The issue occurs because an error route result from the local or main table can be overwritten by a subsequent lookup in the default table.


Remediation

Install update from vendor's website.