CVE-2026-53134
Gravedad CVSS v3.1:
MEDIA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
25/06/2026
Última modificación:
07/07/2026
Descripción
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
netfilter: nft_fib: fix stale stack leak via the OIFNAME register<br />
<br />
For NFT_FIB_RESULT_OIFNAME the destination register is declared with<br />
len = IFNAMSIZ (four 32-bit registers), but on the lookup-fail,<br />
RTN_LOCAL and oif-mismatch paths nft_fib{4,6}_eval() only writes one<br />
register via "*dest = 0". The remaining three registers are left as<br />
whatever was on the stack in nft_do_chain()&#39;s struct nft_regs, and a<br />
downstream expression that loads the register span can leak that<br />
uninitialised kernel stack to userspace.<br />
<br />
The NFTA_FIB_F_PRESENT existence check has the same shape: it is only<br />
meaningful for NFT_FIB_RESULT_OIF, yet it was accepted for any result type<br />
while the eval stores a single byte via nft_reg_store8(), leaving the rest<br />
of the declared span stale.<br />
<br />
Fix both:<br />
<br />
- replace the bare "*dest = 0" in the eval with nft_fib_store_result(),<br />
which strscpy_pad()s the whole IFNAMSIZ for OIFNAME (and is already<br />
used on the other early-return path), and<br />
<br />
- restrict NFTA_FIB_F_PRESENT to NFT_FIB_RESULT_OIF and declare its<br />
destination as a single u8, so the marked span matches the one byte<br />
the eval writes.
Impacto
Puntuación base 3.x
5.50
Gravedad 3.x
MEDIA
Productos y versiones vulnerables
| CPE | Desde | Hasta |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 4.10 (incluyendo) | 5.10.259 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.11 (incluyendo) | 5.15.210 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.16 (incluyendo) | 6.1.176 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.2 (incluyendo) | 6.6.143 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.7 (incluyendo) | 6.12.94 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.13 (incluyendo) | 6.18.36 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.19 (incluyendo) | 7.0.13 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc5:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc6:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc7:*:*:*:*:*:* |
Para consultar la lista completa de nombres de CPE con productos y versiones, ver esta página
Referencias a soluciones, herramientas e información
- https://git.kernel.org/stable/c/3544210609f6d1db282bbdeca639104ef624c393
- https://git.kernel.org/stable/c/6744e49fe51bfba26522acc2d0e9703cb41d8e50
- https://git.kernel.org/stable/c/84d8f58cf28a0415413f43ba7148f7bacd4c1b6e
- https://git.kernel.org/stable/c/8c84885e9790823828bb8084736ea15769b1ac16
- https://git.kernel.org/stable/c/ab185e0c4fb82dfba6fb86f8271e06f931d9c64c
- https://git.kernel.org/stable/c/d19ddef8c327a4773ff81f8e51027d1e0b4cf069
- https://git.kernel.org/stable/c/eb8a8124484dbc3c2b543e207da39bbccb703d31
- https://git.kernel.org/stable/c/eca18feed38b3377a2ec5d1f22af1170c55d0171



