PT-2026-64632 · Linux · Linux

CVE-2026-64411

·

Publicado

2026-07-25

·

Atualizado

2026-07-25

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
netfilter: ebtables: terminate table name before find table lock()
update counters() and compat update counters() forward a user-supplied 32-byte table name to find table lock() without NUL-terminating it. On a lookup miss, find inlist lock() calls try then request module(..., "%s%s", "ebtable ", name), and vsnprintf() reads past the name field and the stack object until it hits a zero byte.
BUG: KASAN: stack-out-of-bounds in string (lib/vsprintf.c:648 lib/vsprintf.c:730) Read of size 1 at addr ffff8880119dfb20 by task exploit/147 Call Trace: ... string (lib/vsprintf.c:648 lib/vsprintf.c:730) vsnprintf (lib/vsprintf.c:2945) request module (kernel/module/kmod.c:150) do update counters.isra.0 (net/bridge/netfilter/ebtables.c:371 net/bridge/netfilter/ebtables.c:380) update counters (net/bridge/netfilter/ebtables.c:1440) do ebt set ctl (net/bridge/netfilter/ebtables.c:2573) nf setsockopt (net/netfilter/nf sockopt.c:101) ip setsockopt (net/ipv4/ip sockglue.c:1424) raw setsockopt (net/ipv4/raw.c:847) sys setsockopt (net/socket.c:2393) ...
compat do replace() shares the same unterminated name via compat copy ebt replace from user(); terminate it there too so all find table lock() callers behave alike. The other callers already terminate the name after the copy.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2026-64411

Produtos afetados

Linux