๐Ÿ” CVE Alert

CVE-2026-64411

UNKNOWN 0.0

netfilter: ebtables: terminate table name before find_table_lock()

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: netfilter: ebtables: terminate table name before find_table_lock() update_counters() and compat_update_counters() forward a user-supplied 32-byte table name to find_table_lock() without NUL-terminating it. On a lookup miss, find_inlist_lock() calls try_then_request_module(..., "%s%s", "ebtable_", name), and vsnprintf() reads past the name field and the stack object until it hits a zero byte. BUG: KASAN: stack-out-of-bounds in string (lib/vsprintf.c:648 lib/vsprintf.c:730) Read of size 1 at addr ffff8880119dfb20 by task exploit/147 Call Trace: ... string (lib/vsprintf.c:648 lib/vsprintf.c:730) vsnprintf (lib/vsprintf.c:2945) __request_module (kernel/module/kmod.c:150) do_update_counters.isra.0 (net/bridge/netfilter/ebtables.c:371 net/bridge/netfilter/ebtables.c:380) update_counters (net/bridge/netfilter/ebtables.c:1440) do_ebt_set_ctl (net/bridge/netfilter/ebtables.c:2573) nf_setsockopt (net/netfilter/nf_sockopt.c:101) ip_setsockopt (net/ipv4/ip_sockglue.c:1424) raw_setsockopt (net/ipv4/raw.c:847) __sys_setsockopt (net/socket.c:2393) ... compat_do_replace() shares the same unterminated name via compat_copy_ebt_replace_from_user(); terminate it there too so all find_table_lock() callers behave alike. The other callers already terminate the name after the copy.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Jul 25, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 4c046ca4e35a83ea32f6e748f54139f5fe2a1d01 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < ab63ccefb9c71627f957a0724c2b9ebc869c6f20 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < c6f539311e58e76aa96feef0f1572b13a564f8a2 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 2664f537ca5bcb2ef3fac2683dcca602e51fad24 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 7436da6c1bc44654b7f11a17e746f6999fd37250 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 6fe8d3cecd20bfaaaf440db3a06ba674d2f2e322 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < b6183b1b88a722b6d8ea0cecc99eba168a15e0be 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < a622d2e9608c9dff47fc2e5759ac7aa3a836b45d
Linux / Linux
2.6.12

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/4c046ca4e35a83ea32f6e748f54139f5fe2a1d01 git.kernel.org: https://git.kernel.org/stable/c/ab63ccefb9c71627f957a0724c2b9ebc869c6f20 git.kernel.org: https://git.kernel.org/stable/c/c6f539311e58e76aa96feef0f1572b13a564f8a2 git.kernel.org: https://git.kernel.org/stable/c/2664f537ca5bcb2ef3fac2683dcca602e51fad24 git.kernel.org: https://git.kernel.org/stable/c/7436da6c1bc44654b7f11a17e746f6999fd37250 git.kernel.org: https://git.kernel.org/stable/c/6fe8d3cecd20bfaaaf440db3a06ba674d2f2e322 git.kernel.org: https://git.kernel.org/stable/c/b6183b1b88a722b6d8ea0cecc99eba168a15e0be git.kernel.org: https://git.kernel.org/stable/c/a622d2e9608c9dff47fc2e5759ac7aa3a836b45d