High severity7.1NVD Advisory· Published Jul 25, 2026· Updated Sep 4, 2026
CVE-2026-64412
CVE-2026-64412
Description
In the Linux kernel, the following vulnerability has been resolved:
netfilter: ebtables: module names must be null-terminated
We need to explicitly check the length, else we may pass non-null terminated string to request_module().
Affected products
3- osv-coords2 versions
>= 4.6.0, < 5.10.261+ 1 more
- (no CPE)range: >= 4.6.0, < 5.10.261
- (no CPE)range: < 7.1.7-1.1
Patches
Vulnerability mechanics
References
8- git.kernel.org/stable/c/084d23f818321390509e9738a0b08bbf46df6425nvdPatch
- git.kernel.org/stable/c/0ddca0f90fa3395111d078ae4399615cf3ea94aanvdPatch
- git.kernel.org/stable/c/13a5f532e3a4fc75c33060a026def1572c208643nvdPatch
- git.kernel.org/stable/c/43dd2332b8a27b3ac5108791680cade654ab0f96nvdPatch
- git.kernel.org/stable/c/5777c8f1c3610786d8482b8f620f40fccaf1542bnvdPatch
- git.kernel.org/stable/c/7b217960e88b5d2d1e8cdcbcaf3bdf6fe199a0c8nvdPatch
- git.kernel.org/stable/c/d2367d99f2455f373996d9ddbe833dbe9f942213nvdPatch
- git.kernel.org/stable/c/da32e78bbb187ed7b137e0007034185570a3a172nvdPatch
News mentions
0No linked articles in our index yet.