Critical severity9.4NVD Advisory· Published Jun 25, 2026· Updated Jul 6, 2026
CVE-2026-53131
CVE-2026-53131
Description
In the Linux kernel, the following vulnerability has been resolved:
netfilter: require Ethernet MAC header before using eth_hdr()
ip6t_eui64, xt_mac, the bitmap:ip,mac, hash:ip,mac, and hash:mac ipset types, and nf_log_syslog access eth_hdr(skb) after either assuming that the skb is associated with an Ethernet device or checking only that the ETH_HLEN bytes at skb_mac_header(skb) lie between skb->head and skb->data.
Make these paths first verify that the skb is associated with an Ethernet device, that the MAC header was set, and that it spans at least a full Ethernet header before accessing eth_hdr(skb).
Affected products
20cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*+ 6 more
- cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*range: >=2.6.12.1,<5.15.210
- cpe:2.3:o:linux:linux_kernel:2.6.12:-:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:2.6.12:rc2:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:2.6.12:rc3:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:2.6.12:rc4:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:2.6.12:rc5:*:*:*:*:*:*
- (no CPE)
- osv-coords12 versionspkg:apk/chainguard/linux-aws-6.12pkg:apk/chainguard/linux-aws-6.18pkg:apk/chainguard/linux-azure-6.18pkg:apk/chainguard/linux-gcp-6.18pkg:apk/chainguard/linux-gcp-6.18-bootc-boot-installedpkg:apk/chainguard/linux-qemu-6.12pkg:apk/chainguard/linux-qemu-6.18pkg:apk/chainguard/linux-qemu-6.18-bootc-boot-installedpkg:apk/chainguard/linux-qemu-melangepkg:apk/chainguard/linux-vmware-6.12pkg:apk/chainguard/linux-vmware-6.18pkg:linux/kernel
< 6.12.95-r0+ 11 more
- (no CPE)range: < 6.12.95-r0
- (no CPE)range: < 6.18.38-r0
- (no CPE)range: < 6.18.38-r0
- (no CPE)range: < 6.18.38-r0
- (no CPE)range: < 6.18.38-r0
- (no CPE)range: < 6.12.95-r0
- (no CPE)range: < 6.18.38-r0
- (no CPE)range: < 6.18.38-r0
- (no CPE)range: < 6.18.36-r0
- (no CPE)range: < 6.12.95-r0
- (no CPE)range: < 6.18.38-r0
- (no CPE)range: >= 2.6.12, < 5.15.210
Patches
Vulnerability mechanics
References
7- git.kernel.org/stable/c/063f43361e884acd7300790e90194430275d0d0cnvdPatch
- git.kernel.org/stable/c/367abcacc13a8e2e7624408b7f593bd1e60e49d9nvdPatch
- git.kernel.org/stable/c/4435888e1bf139d2bfe5911643d4217382136743nvdPatch
- git.kernel.org/stable/c/5d634afb8b83b49de562792fd0d047416a43bd4dnvdPatch
- git.kernel.org/stable/c/62443dc21114c0bbc476fa62973db89743f2f137nvdPatch
- git.kernel.org/stable/c/726abf97566867f808fec9d8a408eb9698bd570anvdPatch
- git.kernel.org/stable/c/cea435ea7e868ea6fdf039bc4f2090c1d829b556nvdPatch
News mentions
1- Android SDK: 13 Kernel Networking CVEs Patched in June 2026 BulletinVypr Intelligence · Jun 25, 2026