CVE-2026-25702
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2026-25702 is an Improper Access Control vulnerability (CWE-284) in the Linux kernel of SUSE Linux Enterprise Server (SLES) 12 SP5 that causes nftables firewall rules to become completely ineffective. The flaw was introduced between kernel commits 9e6d9d4601768c75fdb0bad3fbbe636e748939c2 and 9c294edb7085fb91650bc12233495a8974c5ff2d, and was publicly disclosed on March 5, 2026. It carries a CVSS v3.1 base score of 9.8 (Critical) per Feedly/NVD, though ENISA's EU Vulnerability Database scores it at 7.3 (High) (Feedly, SUSE Bugzilla).

Technical details

The vulnerability stems from an incorrect kernel backport in SUSE's SLES 12 SP5 kernel that breaks the nftables subsystem's ability to enforce firewall rules (CWE-284: Improper Access Control). Because nftables rules are silently rendered non-functional, any network traffic that should be blocked by the firewall policy is instead permitted through without restriction. No authentication, user interaction, or special privileges are required to benefit from this bypass — an attacker simply needs network access to the affected system. A technical write-up describing the root cause as an incorrect kernel backport is available at Infinit Security (Infinit Security).

Impact

The primary impact is a complete failure of nftables-based firewall enforcement on affected SLES 12 SP5 systems, meaning all network traffic filtering rules are bypassed. This exposes services and ports that administrators believe are protected, potentially allowing unauthorized remote access, lateral movement within segmented networks, and data exfiltration. The CVSS v3.1 score reflects high impacts to confidentiality, integrity, and availability, as any network-accessible service on the host becomes reachable by unauthenticated attackers (Feedly).

Exploitation steps

  1. Reconnaissance: Identify SUSE Linux Enterprise Server 12 SP5 hosts using network scanning tools (e.g., Nmap, Shodan) and confirm the target is running a vulnerable kernel version (between commits 9e6d9d46... and 9c294edb...).
  2. Verify firewall bypass: Attempt connections to ports or services that would normally be blocked by nftables rules (e.g., SSH on non-standard ports, internal management interfaces). Successful connections confirm the firewall is non-functional.
  3. Access exposed services: Directly connect to any network service on the target that was previously protected by nftables rules, without needing to bypass any firewall mechanism — the rules are already ineffective.
  4. Achieve objective: Leverage access to exposed services for unauthorized data access, credential harvesting, lateral movement, or further exploitation of application-layer vulnerabilities on services that were previously network-isolated (Feedly, Infinit Security).

Indicators of compromise

  • Logs: Unexpected successful connections in system logs (e.g., /var/log/messages, /var/log/audit/audit.log) to ports or services that nftables rules should be blocking.
  • Network: Inbound traffic to ports that firewall policy designates as blocked, visible via tcpdump or network flow analysis; absence of expected nft drop/reject log entries despite active rule sets.
  • System: Output of nft list ruleset shows rules present, but nft monitor or connection testing reveals rules are not being enforced; kernel version falls within the affected commit range.
  • Process: Unexpected remote sessions (SSH, database connections, etc.) from unauthorized source IPs to services assumed to be firewalled (Feedly).

Mitigation and workarounds

SUSE has released a kernel patch addressing this vulnerability; administrators should update to a kernel version incorporating commit 9c294edb7085fb91650bc12233495a8974c5ff2d or later via official SUSE Linux Enterprise Server security update channels (SUSE Bugzilla). Tenable Nessus plugin 301147 can be used to detect vulnerable systems (Tenable). As a temporary workaround where immediate patching is not possible, administrators should consider switching to iptables/ip6tables for firewall enforcement, implementing network-level segmentation via external firewalls or security groups, or restricting network access to affected hosts until the patch is applied.

Community reactions

The vulnerability received coverage from security aggregators and community blogs shortly after disclosure, including a technical post on Infinit Security describing the root cause as an incorrect kernel backport (Infinit Security). A post on Bluesky from the CyberHub blog noted the issue in March 2026. Tenable added detection support via Nessus plugin 301147, indicating recognition within the vulnerability management community (Tenable). No major vendor statements beyond SUSE's own bugzilla entry have been identified.

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64530CRITICAL9.8
  • Linux Kernel logoLinux Kernel
  • rtla
NoYesJul 26, 2026
CVE-2026-64515HIGH8.3
  • Linux Kernel logoLinux Kernel
  • bpftool
NoYesJul 25, 2026
CVE-2026-17523HIGH7.8
  • Linux Kernel logoLinux Kernel
  • kernel-modules
NoNoJul 27, 2026
CVE-2024-14040HIGH7.8
  • Linux Kernel logoLinux Kernel
  • linux-lowlatency-hwe-5.15
NoYesJul 26, 2026
CVE-2026-64535NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management