SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-64413

HIGH · CVSS 7 EPSS 0.12%

Source: NVD + CISA KEV + EPSS · Published 2026-07-25 · Last synced 2026-08-24

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's netfilter component, specifically within the ebtables functionality, where a sparse CPU possible mask could lead to an uninitialized pointer being freed. This could potentially allow for memory corruption, posing a risk of denial-of-service or arbitrary code execution. Organizations using Linux systems, particularly those relying on ebtables for network filtering, should prioritize addressing this vulnerability to mitigate potential exploitation risks.

CVE
CVE-2026-64413
Severity
HIGH
CVSS
7
EPSS
0.12%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: netfilter: ebtables: zero chainstack array sashiko reports: looking at ebtables table translation, could a sparse cpu_possible_mask lead to an uninitialized pointer free? If cpu_possible_mask is sparse (for example, CPU 0 and CPU 2 are possible, but CPU 1 is not), the allocation loop skips CPU 1. If vmalloc_node() fails at CPU 2, the cleanup loop will blindly decrement and call vfree() on newinfo->chainstack[1]. Not a real-world bug, such allocation isn't expected to fail in the first place.