Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-53211

Gravedad CVSS v3.1:
MEDIA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
25/06/2026
Última modificación:
02/07/2026

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> netfilter: nft_meta_bridge: fix stale stack leak via IIFHWADDR register<br /> <br /> NFT_META_BRI_IIFHWADDR declares its destination register with<br /> len = ETH_ALEN (6 bytes), which the register-init tracking rounds up to<br /> two 32-bit registers (8 bytes). nft_meta_bridge_get_eval() then does<br /> memcpy(dest, br_dev-&gt;dev_addr, ETH_ALEN), writing only 6 bytes and<br /> leaving the upper 2 bytes of the second register as uninitialised<br /> nft_do_chain() stack. A downstream load of that register span leaks<br /> those stale bytes to userspace.<br /> <br /> Zero the second register before the memcpy so the full declared span is<br /> written.

Productos y versiones vulnerables

CPE Desde Hasta
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.18 (incluyendo) 6.18.36 (excluyendo)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.19 (incluyendo) 7.0.13 (excluyendo)
cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc5:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc6:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc7:*:*:*:*:*:*