CVE-2026-52912Exploit(linux / linux_kernel)

HIGHCVSS 7.8 · HIGH

Exploitation observed; activity peaked at 4 mentions and remains active

Immediate actions

  • Patch linux linux_kernel systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_queue: hold bridge skb->dev while queued br_pass_frame_up() rewrites skb->dev from the ingress port to the bridge master before queueing bridge LOCAL_IN packets. NFQUEUE only holds references on state.in/out and bridge physdevs, so a queued bridge packet can retain a freed bridge master in skb->dev until reinjection. When the verdict is reinjected later, br_netif_receive_skb() re-enters the receive path with skb->dev still pointing at the freed bridge master, triggering a use-after-free. Store skb->dev in the queue entry, hold a reference on it for the queue lifetime, and use the saved device when dropping queued packets during NETDEV_DOWN handling.

7.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 11 mentions across 7 observed days

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 6 signals
  • PoC mentioned or linked in 9 signals
  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 9 signals
  • General: 3 classified signals
  • Peaked 4d ago at 4 mentions (2026-08-24); latest day: 1
  • 11 total mentions across 7 days

Affected systems

Vendors
Products
linux_kernel

1 version affected across 1 product

Deep dive

Activity timeline11 mentions / 7d
01234Mentions · 2026-08-22: 1Mentions · 2026-08-23: 1Mentions · 2026-08-24: 4Mentions · 2026-08-25: 2Mentions · 2026-08-31: 1Mentions · 2026-09-12: 1Mentions · 2026-09-15: 1PoC Mentioned / Linked · 2026-08-22: 1PoC Mentioned / Linked · 2026-08-23: 1PoC Mentioned / Linked · 2026-08-24: 4PoC Mentioned / Linked · 2026-08-31: 1PoC Mentioned / Linked · 2026-09-12: 1PoC Mentioned / Linked · 2026-09-15: 1Exploit Tool / Code · 2026-08-22: 1Exploit Tool / Code · 2026-08-23: 1Exploit Tool / Code · 2026-08-24: 3Exploit Tool / Code · 2026-08-31: 1Active Exploitation · 2026-09-12: 1Patch / Workaround · 2026-08-22: 1Patch / Workaround · 2026-08-23: 1Patch / Workaround · 2026-08-24: 1Patch / Workaround · 2026-09-15: 1Technical Details · 2026-08-22: 1Technical Details · 2026-08-23: 1Technical Details · 2026-08-24: 3Technical Details · 2026-08-25: 1Technical Details · 2026-08-31: 1Technical Details · 2026-09-12: 1Technical Details · 2026-09-15: 108-2208-2308-2408-2508-3109-1209-15
Signal classification3 categories
Exploit
436.4%
PoC
436.4%
General
327.3%
Referenced assets16 URLs
Classification over time
DateTotalLabels
2026-08-221
Exploit1
2026-08-231
PoC1
2026-08-244
Exploit2PoC2
2026-08-252
General2
2026-08-311
Exploit1
2026-09-121
General1
2026-09-151
PoC1
Full discourse11 posts
  • Nebula Security@nebusecurity
    Exploit

    Today's exploit is for the latest Fedora 44, a UAF in netfilter, CVE-2026-52912. It was introduced in Mar 2016 and fixed upstream in May 2026. Discovered and exploited by the NebuSec security pipeline. (RANDOM_KMALLOC_CACHES + SELinux) Exp source code: https://github.com/NebuSec/CyberMeowfia/tree/main/security-research/Linux-CVE-2026-52912-Fedora-6.19.10-300 https://t.co/WZO8z1uPBU

    Post summary

    The post shares a working exploit for the UAF vulnerability CVE‑2026‑52912 in Fedora 44, includes source code, notes that the patch is upstream, and makes no claim of wild exploitation.

    22021275012.0K
    6.9K followersView on X
  • Rıdvan Yağlı@ridvanyagli
    PoC

    🔴 Nebula Security, Linux kernel'deki Netfilter kaynaklı Use-After-Free açığı CVE-2026-52912 için Fedora 44 (kernel 6.19.10-300) üzerinde çalışan bir PoC/exploit yayınladı. Bu açık Mayıs 2026'da upstream olarak düzeltildi. PoC: https://github.com/NebuSec/CyberMeowfia/tree/main/security-research/Linux-CVE-2026-52912-Fedora-6.19.10-300 https://x.com/nebusecurity/status/2091305715965239746/video/1

    Post summary

    Nebula Security disclosed a Proof of Concept and exploit code for the Netfilter Use‑After‑Free CVE‑2026‑52912, with the upstream fix already applied as of May 2026.

    0501891.2K
    2.4K followersView on X
  • Daily CyberSecurity@Daily_CyberSec
    Exploit

    CVE-2026-52912, a Linux kernel netfilter use-after-free, now has public PoC exploit code enabling root privilege escalation. #CVE202652912 #LinuxKernel #PrivilegeEscalation #Netfilter #UseAfterFree #PoC #Exploit #InfoSec http://securityonline.info/cve-2026-52912-linux-kernel-root-poc/

    Post summary

    A public PoC exploit for CVE-2026-52912 is now available, allowing root privilege escalation via a Linux kernel netfilter use‑after‑free, but no active exploitation has been reported.

    0201641.0K
    13.0K followersView on X
  • dbugs@ptdbugs
    Exploit

    A PoC/exploit has been discovered for vulnerability CVE-2026-52912 Vendor: Linux Product: Linux Kernel Description: A use-after-free issue exists in the netfilter nf queue component. The br pass frame up() function rewrites skb->dev from the ingress port to the bridge master before queueing bridge LOCAL IN packets. Because NFQUEUE only holds references on http://state.in/out and bridge physdevs, a queued bridge packet may retain a reference to a freed bridge master in skb->dev until reinjection. When the verdict is later reinjected, br netif receive skb() re-enters the receive path while skb->dev still points to the freed bridge master, leading to the use-after-free condition. Link: https://github.com/NebuSec/CyberMeowfia/blob/main/security-research/Linux-CVE-2026-52912-Fedora-6.19.10-300/exploit.c #dbugs_vuln

    Post summary

    A PoC and functional exploit for CVE-2026-52912, a use‑after‑free in the Linux Kernel's netfilter nf queue component, has been released with source code available on GitHub. The post does not indicate active exploitation in the wild or any patch status.

    100941.1K
    3.6K followersView on X
  • Mr. OS@ksg93rd
    General

    #Analytics #Threat_Research An analytical review of the main cybersecurity events (Sep 05-12, 2026) 1⃣ Sonicwall SMA1000 Attack https://hunt.io/blog/sonicwall-sma1000-uk-council-attack // CVE-2026-15409 2⃣ Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability https://hunt.io/blog/sonicwall-sma1000-uk-council-attack 3⃣ Next Nightmare Eclipse Vulnerability https://github.com/MSNightmare/ShieldCrash/blob/main/README.md // Microsoft has failed to properly patch ShieldBreak CVE-2026-69414.. 4⃣ FortiPAM Vulnerability https://amibeingpwned.com/blog/fortinet-pam-vuln // CVE-2026-84388 5⃣ Researchers from Nebula Security have disclosed 18 vulnerabilities in the Linux kernel https://www.openwall.com/lists/oss-security/2026/09/08/1 // CVE-2026-80714, CVE-2026-74597, CVE-2026-74581, CVE-2026-74480, CVE-2026-72255, CVE-2026-72137, CVE-2026-68376, CVE-2026-68162, CVE-2026-64560,  CVE-2026-63834, CVE-2026-52933, CVE-2026-52929, CVE-2026-52924, CVE-2026-52923, CVE-2026-52912, CVE-2026-43501, CVE-2026-43502, CVE-2026-43074, CVE-2026-43042, CVE-2026-31678, CVE-2026-31659, CVE-2026-23274 6⃣ Netscaler ADC Exploit 7⃣ Critical vulnerabilities in MikroTik RouterOS https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/ 8⃣ GRAYRABBIT One-click backdoor // One click. Three critical failures. One backdoor https://www.gendigital.com/blog/insights/research/one-click-backdoor-sogou 9⃣ Attacks using browser-in-browser (BiTB) phishing techniques https://www.huntress.com/blog/phishing-bitb-rmm-attacks 🔟 Beltdown: Escaping the Claude Code sandbox https://www.accomplish.ai/blog/beltdown-escaping-the-claude-code-sandbox/ // An untrusted repository opened in Claude Code can escape the macOS sandbox and run commands on your computer as your privileged user http://www.Geniebot.pro http://www.cyberpocket.org

    Post summary

    This post offers an overview of several high-severity CVEs, noting active exploitation in MikroTik RouterOS but lacking detailed exploit or patch information.

    01052600
    3.4K followersView on X
  • Cyber Meowfia@cybermeowfia
    Exploit

    AUG 22: Exploit for the latest Fedora 44, a UAF in netfilter, CVE-2026-52912. It was introduced in Mar 2016 and fixed upstream in May 2026. Discovered and exploited by the NebuSec security pipeline. (RANDOM_KMALLOC_CACHES + SELinux) Exp source code: https://github.com/NebuSec/CyberMeowfia/tree/main/security-research/Linux-CVE-2026-52912-Fedora-6.19.10-300 https://t.co/I4HqKW2Wbm

    Post summary

    The tweet announces an exploit for CVE-2026-52912, a UAF in netfilter, and shares a GitHub link to exploit source code, confirming technical details and exploit availability without reporting active in-the-wild exploitation.

    00042445
    439 followersView on X
  • moton@moton
    PoC

    CVE-2026-52912: Linux Kernel Root Exploit PoC Out - https://securityonline.info/cve-2026-52912-linux-kernel-root-poc/

    Post summary

    The post announces that a proof‑of‑concept for CVE‑2026‑52912—a Linux kernel root exploit—has been released and shares a link to the code, without mentioning active attacks, patches, or detailed technical information.

    00030198
    758 followersView on X
  • Threat Landscape@LandscapeThreat
    PoC

    Researchers disclosed CVE-2026-43502, a Linux kernel local privilege-escalation vulnerability in the RDS zerocopy send path, alongside 20 additional exploitable Linux bugs. - An unprivileged local user can obtain root privileges without Linux capabilities or user namespaces when required networking, asynchronous I/O, and RDS components are enabled. - The vulnerability affects kernels from Linux v4.17 and was demonstrated on openSUSE with kernel 6.4.0-150600.23.100. - The issue was fixed by commit 44b550d88b26, first included in Linux v7.1-rc3; public exploits for the listed vulnerabilities are available. VULNERABILITY CVE-2026-23274 CVE-2026-31659 CVE-2026-31678 CVE-2026-43042 CVE-2026-43074 CVE-2026-43501 CVE-2026-43502 CVE-2026-52912 CVE-2026-52923 CVE-2026-52924 CVE-2026-52929 CVE-2026-52933 CVE-2026-63834 CVE-2026-64560 CVE-2026-68162 CVE-2026-68376 CVE-2026-72137 CVE-2026-72255 CVE-2026-74480 CVE-2026-74581 CVE-2026-74597 CVE-2026-80714

    Post summary

    Researchers disclosed 21 Linux kernel vulnerabilities, including CVE-2026-43502 (RDS LPE), affecting kernels v4.17+, with a fix in v7.1-rc3 and public exploits available.

    0002055
    91 followersView on X
  • OS開発者@hacker_infra
    General

    Red hatが重大度あげるな。 その分補正パッケージの優先度があがるか? Hello OS開発者, Thank you for reporting these exploit to Red Hat Product Security. We have re-evaluated CVE-2026-52912 and being treated as Important, Regards, Rohit

    Post summary

    The text informs that Red Hat has re‑evaluated CVE‑2026‑52912 as "Important", but provides no further technical, exploit, or patch details.

    00020252
    2.9K followersView on X
  • toolshed@toolshed_labs
    General

    @ptdbugs CVE-2026-52912 needs local access and the ability to create user namespaces. Containers often allow that combination, making it a real escape path.

    Post summary

    The tweet highlights that CVE-2026-52912 requires local access and the ability to create user namespaces—a condition often found in container environments—pointing to a potential privilege‑escalation escape path, but provides no PoC, exploit code, patch information, or evidence of active exploitation.

    0001092
    66 followersView on X
  • Upwind Security MDR@UpwindMDR
    PoC

    🚨High - Linux kernel local privilege escalation via netfilter/nf_queue UAF (CVE-2026-52912) NFQUEUE doesn't take a reference on the bridge master in skb->dev, so deleting the bridge while a packet is queued leaves a dangling pointer — an ACCEPT verdict then triggers a use-after-free. Public unprivileged LPE-to-root PoC on Fedora 44 kernel 6.19.10-300. Requires unprivileged user namespaces to reach the bridge and NFQUEUE setup. 👉Affected: Linux kernel | Fixed in 5.10.259, 5.15.209, 6.1.175, 6.6.142, 6.12.92, 6.18.34. Fedora 44: upgrade to 7.0.11

    Post summary

    The notice reports a confirmed Linux kernel local privilege escalation vulnerability (CVE‑2026‑52912), highlights a public PoC, and provides patch/upgrade guidance.

    0000092
    294 followersView on X
CPE platform detail5 entries

5 of 5 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---
OSlinuxlinux_kernel7.1--
OSlinuxlinux_kernel7.1--
OSlinuxlinux_kernel7.1--
OSlinuxlinux_kernel7.1--

Explore more