CVE-2026-52927
Severity CVSS v4.0:
Pending analysis
Type:
CWE-125
Out-of-bounds Read
Publication date:
24/06/2026
Last modified:
08/07/2026
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
netfilter: ebtables: fix OOB read in compat_mtw_from_user<br />
<br />
Luxiao Xu says:<br />
<br />
The function compat_mtw_from_user() converts ebtables extensions from<br />
32-bit user structures to kernel native structures. However, it lacks<br />
proper validation of the user-supplied match_size/target_size.<br />
<br />
When certain extensions are processed, the kernel-side translation<br />
logic may perform memory accesses based on the extension&#39;s expected<br />
size. If the user provides a size smaller than what the extension<br />
requires, it results in an out-of-bounds read as reported by KASAN.<br />
<br />
This fix introduces a check to ensure match_size is at least as large<br />
as the extension&#39;s required compatsize. This covers matches, watchers,<br />
and targets, while maintaining compatibility with standard targets.<br />
<br />
AFAIU this is relevant for matches that need to go though<br />
match->compat_from_user() call. Those that use plain memcpy with the<br />
user-provided size are ok because the caller checks that size vs the<br />
start of the next rule entry offset (which itself is checked vs. total<br />
size copied from userspace).<br />
<br />
The ->compat_from_user() callbacks assume they can read compatsize bytes,<br />
so they need this extra check.<br />
<br />
Based on an earlier patch from Luxiao Xu.
Impact
Base Score 3.x
7.80
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 2.6.34 (including) | 5.10.259 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.11 (including) | 5.15.210 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.16 (including) | 6.1.176 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.2 (including) | 6.6.143 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.7 (including) | 6.12.93 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.13 (including) | 6.18.35 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.19 (including) | 7.0.12 (excluding) |
| cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc5:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/21af4c030567d2e6c89bb927bc18b51fba52a400
- https://git.kernel.org/stable/c/7ad0e463fc7eafae2141cc38054264636f8b3e94
- https://git.kernel.org/stable/c/a27cb7325a6c69970041c7f8541fafed5a1ea3ec
- https://git.kernel.org/stable/c/bf8e8eac7ede51dc318e06acef5a896dcbba7595
- https://git.kernel.org/stable/c/d7a8fb6f10d55a1c37b0bf8c20cca24dffd76e00
- https://git.kernel.org/stable/c/dad9ebf8107955bb54bd3f9cf22591b6ff37bac1
- https://git.kernel.org/stable/c/f438d1786d657d57790c5d138d6db3fc9fdac392
- https://git.kernel.org/stable/c/fcc4c043d137e7f1de4673dba1f3116e45377c67



