CVE-2026-64412

Source
https://cve.org/CVERecord?id=CVE-2026-64412
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64412.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-64412
Downstream
Related
Published
2026-07-25T08:50:52.946Z
Modified
2026-08-18T03:31:07.230466036Z
Severity
  • 7.1 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H CVSS Calculator
Summary
netfilter: ebtables: module names must be null-terminated
Details

In the Linux kernel, the following vulnerability has been resolved:

netfilter: ebtables: module names must be null-terminated

We need to explicitly check the length, else we may pass non-null terminated string to request_module().

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64412.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
bcf4934288402be3464110109a4dae3bd6fb3e93
Fixed
43dd2332b8a27b3ac5108791680cade654ab0f96
Fixed
5777c8f1c3610786d8482b8f620f40fccaf1542b
Fixed
0ddca0f90fa3395111d078ae4399615cf3ea94aa
Fixed
d2367d99f2455f373996d9ddbe833dbe9f942213
Fixed
da32e78bbb187ed7b137e0007034185570a3a172
Fixed
13a5f532e3a4fc75c33060a026def1572c208643
Fixed
7b217960e88b5d2d1e8cdcbcaf3bdf6fe199a0c8
Fixed
084d23f818321390509e9738a0b08bbf46df6425

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64412.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.6.0
Fixed
5.10.261
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.212
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.178
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.145
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.96
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.39
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64412.json"