CVE-2026-64413
In the Linux kernel, the following vulnerability has been resolved: netfilter: ebtables: zero chainstack array sashiko reports: looking at ebtables table translation, could a sparse cpu_possible_mask lead to an uninitialized pointer free? If cpu_possible_mask is sparse (for example, CPU 0 and CPU 2 are possible, but CPU 1 is not), the allocation loop skips CPU 1. If vmalloc_node() fails at CPU 2, the cleanup loop will blindly decrement and call vfree() on newinfo->chainstack[1]. Not a real-world bug, such allocation isn't expected to fail in the first place.
Schwachstellenklasse
In the Linux kernel, the following vulnerability has been resolved: netfilter: ebtables: zero chainstack array sashiko reports: looking at ebtables table translation, could a sparse cpu_possible_mask lead to an uninitialized pointer free? If cpu_possible_mask is sparse (for example, CPU 0 and CPU 2 are possible, but CPU 1 is not), the allocation loop skips CPU 1. If vmalloc_node() fails at CPU 2, the cleanup loop will blindly decrement and call vfree() on newinfo->chainstack[1]. Not a real-world bug, such allocation isn't expected to fail in the first place.
Betroffene Produkte
- linux linux_kernel
Quellen
- https://git.kernel.org/stable/c/29bf41a9b59aff9f6197df58641a00037d567ca8
- https://git.kernel.org/stable/c/2ade612967e2cdfb9290ebcb773f302c82f311fa
- https://git.kernel.org/stable/c/42bef500d07b5769d916e9122a3e3fa3fd2245ef
- https://git.kernel.org/stable/c/5ee856e4208acafaaaf7b84824d39b78c21345d6
- https://git.kernel.org/stable/c/9e6c5169db423e51dcc66a73fd15409c0d38e088
- https://git.kernel.org/stable/c/9f74d28e903fa4fdf82f870d0aeadddc8196e41c
Finden Sie die Schwachstelle, bevor es ein Angreifer tut.
Melden Sie sich mit GitHub an und starten Sie Ihr erstes Audit in weniger als einer Minute. Für den kostenlosen Plan ist keine Kreditkarte nötig.