Executive brief
A vulnerability was identified in the Linux kernel's networking component (ebtables) that could allow a local user to trigger an information leak or a system crash. The issue occurs because the system fails to properly handle certain network table names provided by users, leading to an out-of-bounds memory read. While this primarily impacts system stability, it could potentially be used to gather sensitive information from the computer's memory.
Technical details
A stack-out-of-bounds read vulnerability exists in net/bridge/netfilter/ebtables.c within the Linux kernel. The functions update_counters() and compat_update_counters() accept a 32-byte table name from userspace via setsockopt but fail to ensure NUL-termination before passing it to find_table_lock(). If a lookup miss occurs, find_inlist_lock() triggers try_then_request_module(), which uses vsnprintf() to format a module name. Because the input is not terminated, vsnprintf() reads past the intended buffer until it encounters a zero byte in stack memory. This can result in a kernel oops (as seen in KASAN reports) or potentially leak stack data. The fix involves explicitly NUL-terminating the name buffer after copying it from userspace.
Affected products
- Linux Linux Kernel 4.19.y, 5.4.y, 5.10.y, 5.15.y, 6.1.y, 6.6.y, 6.9.y, 6.10.y
Timeline
- 2026-07-05: disclosed: Vulnerability reported by Weiming Shi
- 2026-07-24: patched: Fix committed to stable trees by Greg Kroah-Hartman
- 2026-07-25: advisory: CVE-2026-64411 published
References
- https://git.kernel.org/stable/c/2664f537ca5bcb2ef3fac2683dcca602e51fad24
- https://git.kernel.org/stable/c/4c046ca4e35a83ea32f6e748f54139f5fe2a1d01
- https://git.kernel.org/stable/c/6fe8d3cecd20bfaaaf440db3a06ba674d2f2e322
- https://git.kernel.org/stable/c/7436da6c1bc44654b7f11a17e746f6999fd37250
- https://git.kernel.org/stable/c/a622d2e9608c9dff47fc2e5759ac7aa3a836b45d
- https://git.kernel.org/stable/c/ab63ccefb9c71627f957a0724c2b9ebc869c6f20
- https://git.kernel.org/stable/c/b6183b1b88a722b6d8ea0cecc99eba168a15e0be