IM
IronMonkey Threat Research

CVE-2026-64413 HIGH

Published: 2026-07-25 | Last Modified: 2026-09-08 | Status: Modified

Description

In the Linux kernel, the following vulnerability has been resolved: netfilter: ebtables: zero chainstack array sashiko reports: looking at ebtables table translation, could a sparse cpu_possible_mask lead to an uninitialized pointer free? If cpu_possible_mask is sparse (for example, CPU 0 and CPU 2 are possible, but CPU 1 is not), the allocation loop skips CPU 1. If vmalloc_node() fails at CPU 2, the cleanup loop will blindly decrement and call vfree() on newinfo->chainstack[1]. Not a real-world bug, such allocation isn't expected to fail in the first place.

CVSS Metrics

Base Score: 7.0 (HIGH)

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack VectorLOCAL
Attack ComplexityHIGH
Privileges RequiredLOW
User InteractionNONE
ScopeUNCHANGED
Confidentiality ImpactHIGH
Integrity ImpactHIGH
Availability ImpactHIGH

Source: 416baaa9-dc9f-4396-8d5f-8c081fb06d67

Type: Secondary

Exploitability Score: 1.0

Impact Score: 5.9

Weaknesses

Source Type Description
[email protected] Primary
en CWE-908

Affected Products

Vendor Product Version Update Type
linux linux_kernel * <built-in method update of dict object at 0x7d24245ad780> Operating System
linux linux_kernel * <built-in method update of dict object at 0x7d23a59842c0> Operating System
linux linux_kernel * <built-in method update of dict object at 0x7d24246c1b80> Operating System
linux linux_kernel * <built-in method update of dict object at 0x7d24604ad7c0> Operating System
linux linux_kernel * <built-in method update of dict object at 0x7d2424504f00> Operating System
linux linux_kernel * <built-in method update of dict object at 0x7d2424507100> Operating System
linux linux_kernel * <built-in method update of dict object at 0x7d24246c2400> Operating System
linux linux_kernel 2.6.12 <built-in method update of dict object at 0x7d23a59859c0> Operating System
linux linux_kernel 2.6.12 <built-in method update of dict object at 0x7d242a875e80> Operating System
linux linux_kernel 2.6.12 <built-in method update of dict object at 0x7d2424507640> Operating System
linux linux_kernel 2.6.12 <built-in method update of dict object at 0x7d23a5984b00> Operating System
linux linux_kernel 2.6.12 <built-in method update of dict object at 0x7d23a5986f80> Operating System
linux linux_kernel 7.2 <built-in method update of dict object at 0x7d24245a0400> Operating System
linux linux_kernel 7.2 <built-in method update of dict object at 0x7d23a7093f40> Operating System

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:2.6.12:-:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:2.6.12:rc2:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:2.6.12:rc3:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:2.6.12:rc4:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:2.6.12:rc5:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:7.2:rc1:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:7.2:rc2:*:*:*:*:*:*

References

Notification
Message here