CVE-2026-53211 PUBLISHED

netfilter: nft_meta_bridge: fix stale stack leak via IIFHWADDR register

Assigner: Linux
Reserved: 09.06.2026 Published: 25.06.2026 Updated: 25.06.2026

In the Linux kernel, the following vulnerability has been resolved:

netfilter: nft_meta_bridge: fix stale stack leak via IIFHWADDR register

NFT_META_BRI_IIFHWADDR declares its destination register with len = ETH_ALEN (6 bytes), which the register-init tracking rounds up to two 32-bit registers (8 bytes). nft_meta_bridge_get_eval() then does memcpy(dest, br_dev->dev_addr, ETH_ALEN), writing only 6 bytes and leaving the upper 2 bytes of the second register as uninitialised nft_do_chain() stack. A downstream load of that register span leaks those stale bytes to userspace.

Zero the second register before the memcpy so the full declared span is written.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from cbd2257dc96e3e46217540fcb095a757ffa20d96 to 07acb9798477535933bd658ac9fa85b6cb10d995 (excl.)
  • affected from cbd2257dc96e3e46217540fcb095a757ffa20d96 to f1e81d571e375d10e50e852223593493d98c1bac (excl.)
  • affected from cbd2257dc96e3e46217540fcb095a757ffa20d96 to c7d573551f9286100a055ef696cde6af54549677 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 6.18 is affected
  • unaffected from 0 to 6.18 (excl.)
  • unaffected from 6.18.36 to 6.18.* (incl.)
  • unaffected from 7.0.13 to 7.0.* (incl.)
  • unaffected from 7.1 to * (incl.)

References