Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-53013

Gravedad CVSS v3.1:
MEDIA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
24/06/2026
Última modificación:
14/07/2026

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> macvlan: fix macvlan_get_size() not reserving space for IFLA_MACVLAN_BC_CUTOFF<br /> <br /> macvlan_get_size() does not account for IFLA_MACVLAN_BC_CUTOFF, but<br /> macvlan_fill_info() conditionally includes it when port-&gt;bc_cutoff != 1.<br /> This causes nla_put_s32() to fail with -EMSGSIZE when the netlink skb<br /> runs out of space, triggering a WARN_ON in rtnetlink and preventing the<br /> interface from being dumped.<br /> <br /> The bug can be reproduced with:<br /> <br /> ip link add macvlan0 link eth0 type macvlan mode bridge<br /> ip link set macvlan0 type macvlan bc_cutoff 0<br /> ip -d link show macvlan0 # fails with -EMSGSIZE<br /> <br /> The bc_cutoff feature was added in commit 954d1fa1ac93 ("macvlan: Add<br /> netlink attribute for broadcast cutoff"), which added the nla_put_s32()<br /> call in macvlan_fill_info() but missed adding the corresponding<br /> nla_total_size(4) in macvlan_get_size(). A follow-up commit<br /> 55cef78c244d ("macvlan: add forgotten nla_policy for<br /> IFLA_MACVLAN_BC_CUTOFF") fixed the missing nla_policy entry but still<br /> did not fix the size calculation.

Productos y versiones vulnerables

CPE Desde Hasta
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.4 (incluyendo) 6.6.141 (excluyendo)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.7 (incluyendo) 6.12.91 (excluyendo)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.13 (incluyendo) 6.18.33 (excluyendo)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.19 (incluyendo) 7.0.10 (excluyendo)