CVE-2026-64412
HIGH severity · CVSS 7.1
7.1CVSS HIGH
Summary
In the Linux kernel, the following vulnerability has been resolved: netfilter: ebtables: module names must be null-terminated We need to explicitly check the length, else we may pass non-null terminated string to request_module().
Impact & exploitability
Attack vectorLocal
Attack complexityLow
Privileges requiredLow
User interactionNone
Confidentiality impactHigh
Integrity impactNone
Availability impactHigh
Exploit probability (EPSS)0%
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Affected products we track (1)
Recommendation
Apply the vendor fix promptly. Open any affected product above for its exact safe version.
Official patch: https://git.kernel.org/stable/c/084d23f818321390509e9738a0b08bbf46df6425 ↗
Additional information
- NVD record
- https://git.kernel.org/stable/c/084d23f818321390509e9738a0b08bbf46df6425Patch
- https://git.kernel.org/stable/c/0ddca0f90fa3395111d078ae4399615cf3ea94aaPatch
- https://git.kernel.org/stable/c/13a5f532e3a4fc75c33060a026def1572c208643Patch
- https://git.kernel.org/stable/c/43dd2332b8a27b3ac5108791680cade654ab0f96Patch
- https://git.kernel.org/stable/c/5777c8f1c3610786d8482b8f620f40fccaf1542bPatch
- https://git.kernel.org/stable/c/7b217960e88b5d2d1e8cdcbcaf3bdf6fe199a0c8Patch
- https://git.kernel.org/stable/c/d2367d99f2455f373996d9ddbe833dbe9f942213Patch
- https://git.kernel.org/stable/c/da32e78bbb187ed7b137e0007034185570a3a172Patch