
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-25702 is an Improper Access Control vulnerability (CWE-284) in the Linux kernel of SUSE Linux Enterprise Server (SLES) 12 SP5 that causes nftables firewall rules to become completely ineffective. The flaw was introduced between kernel commits 9e6d9d4601768c75fdb0bad3fbbe636e748939c2 and 9c294edb7085fb91650bc12233495a8974c5ff2d, and was publicly disclosed on March 5, 2026. It carries a CVSS v3.1 base score of 9.8 (Critical) per Feedly/NVD, though ENISA's EU Vulnerability Database scores it at 7.3 (High) (Feedly, SUSE Bugzilla).
The vulnerability stems from an incorrect kernel backport in SUSE's SLES 12 SP5 kernel that breaks the nftables subsystem's ability to enforce firewall rules (CWE-284: Improper Access Control). Because nftables rules are silently rendered non-functional, any network traffic that should be blocked by the firewall policy is instead permitted through without restriction. No authentication, user interaction, or special privileges are required to benefit from this bypass — an attacker simply needs network access to the affected system. A technical write-up describing the root cause as an incorrect kernel backport is available at Infinit Security (Infinit Security).
The primary impact is a complete failure of nftables-based firewall enforcement on affected SLES 12 SP5 systems, meaning all network traffic filtering rules are bypassed. This exposes services and ports that administrators believe are protected, potentially allowing unauthorized remote access, lateral movement within segmented networks, and data exfiltration. The CVSS v3.1 score reflects high impacts to confidentiality, integrity, and availability, as any network-accessible service on the host becomes reachable by unauthenticated attackers (Feedly).
9e6d9d46... and 9c294edb...)./var/log/messages, /var/log/audit/audit.log) to ports or services that nftables rules should be blocking.tcpdump or network flow analysis; absence of expected nft drop/reject log entries despite active rule sets.nft list ruleset shows rules present, but nft monitor or connection testing reveals rules are not being enforced; kernel version falls within the affected commit range.SUSE has released a kernel patch addressing this vulnerability; administrators should update to a kernel version incorporating commit 9c294edb7085fb91650bc12233495a8974c5ff2d or later via official SUSE Linux Enterprise Server security update channels (SUSE Bugzilla). Tenable Nessus plugin 301147 can be used to detect vulnerable systems (Tenable). As a temporary workaround where immediate patching is not possible, administrators should consider switching to iptables/ip6tables for firewall enforcement, implementing network-level segmentation via external firewalls or security groups, or restricting network access to affected hosts until the patch is applied.
The vulnerability received coverage from security aggregators and community blogs shortly after disclosure, including a technical post on Infinit Security describing the root cause as an incorrect kernel backport (Infinit Security). A post on Bluesky from the CyberHub blog noted the issue in March 2026. Tenable added detection support via Nessus plugin 301147, indicating recognition within the vulnerability management community (Tenable). No major vendor statements beyond SUSE's own bugzilla entry have been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."