CVE-2026-64412 PUBLISHED

netfilter: ebtables: module names must be null-terminated

Assigner: Linux
Reserved: 19.07.2026 Published: 25.07.2026 Updated: 25.07.2026

In the Linux kernel, the following vulnerability has been resolved:

netfilter: ebtables: module names must be null-terminated

We need to explicitly check the length, else we may pass non-null terminated string to request_module().

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from bcf4934288402be3464110109a4dae3bd6fb3e93 to 43dd2332b8a27b3ac5108791680cade654ab0f96 (excl.)
  • affected from bcf4934288402be3464110109a4dae3bd6fb3e93 to 5777c8f1c3610786d8482b8f620f40fccaf1542b (excl.)
  • affected from bcf4934288402be3464110109a4dae3bd6fb3e93 to 0ddca0f90fa3395111d078ae4399615cf3ea94aa (excl.)
  • affected from bcf4934288402be3464110109a4dae3bd6fb3e93 to d2367d99f2455f373996d9ddbe833dbe9f942213 (excl.)
  • affected from bcf4934288402be3464110109a4dae3bd6fb3e93 to da32e78bbb187ed7b137e0007034185570a3a172 (excl.)
  • affected from bcf4934288402be3464110109a4dae3bd6fb3e93 to 13a5f532e3a4fc75c33060a026def1572c208643 (excl.)
  • affected from bcf4934288402be3464110109a4dae3bd6fb3e93 to 7b217960e88b5d2d1e8cdcbcaf3bdf6fe199a0c8 (excl.)
  • affected from bcf4934288402be3464110109a4dae3bd6fb3e93 to 084d23f818321390509e9738a0b08bbf46df6425 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 4.6 is affected
  • unaffected from 0 to 4.6 (excl.)
  • unaffected from 5.10.261 to 5.10.* (incl.)
  • unaffected from 5.15.212 to 5.15.* (incl.)
  • unaffected from 6.1.178 to 6.1.* (incl.)
  • unaffected from 6.6.145 to 6.6.* (incl.)
  • unaffected from 6.12.96 to 6.12.* (incl.)
  • unaffected from 6.18.39 to 6.18.* (incl.)
  • unaffected from 7.1.4 to 7.1.* (incl.)
  • unaffected from 7.2-rc3 to * (incl.)

References