PT-2026-64632 · Linux · Linux
CVE-2026-64411
·
Publicado
2026-07-25
·
Atualizado
2026-07-25
Nenhuma
Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
netfilter: ebtables: terminate table name before find table lock()
update counters() and compat update counters() forward a user-supplied
32-byte table name to find table lock() without NUL-terminating it. On a
lookup miss, find inlist lock() calls try then request module(..., "%s%s",
"ebtable ", name), and vsnprintf() reads past the name field and the
stack object until it hits a zero byte.
BUG: KASAN: stack-out-of-bounds in string (lib/vsprintf.c:648 lib/vsprintf.c:730)
Read of size 1 at addr ffff8880119dfb20 by task exploit/147
Call Trace:
...
string (lib/vsprintf.c:648 lib/vsprintf.c:730)
vsnprintf (lib/vsprintf.c:2945)
request module (kernel/module/kmod.c:150)
do update counters.isra.0 (net/bridge/netfilter/ebtables.c:371 net/bridge/netfilter/ebtables.c:380)
update counters (net/bridge/netfilter/ebtables.c:1440)
do ebt set ctl (net/bridge/netfilter/ebtables.c:2573)
nf setsockopt (net/netfilter/nf sockopt.c:101)
ip setsockopt (net/ipv4/ip sockglue.c:1424)
raw setsockopt (net/ipv4/raw.c:847)
sys setsockopt (net/socket.c:2393)
...
compat do replace() shares the same unterminated name via
compat copy ebt replace from user(); terminate it there too so all
find table lock() callers behave alike. The other callers already
terminate the name after the copy.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Linux