CVE-2026-53131
published 2026-06-25CVE-2026-53131: In the Linux kernel, the following vulnerability has been resolved: netfilter: require Ethernet MAC header before using eth_hdr() `ip6t_eui64`, `xt_mac`, the…
PriorityP352critical9.4CVSS 3.1
AVNACLPRNUINSUCHILAH
EPSS
0.43%
34.7th percentile
In the Linux kernel, the following vulnerability has been resolved:
netfilter: require Ethernet MAC header before using eth_hdr()
`ip6t_eui64`, `xt_mac`, the `bitmap:ip,mac`, `hash:ip,mac`, and
`hash:mac` ipset types, and `nf_log_syslog` access `eth_hdr(skb)`
after either assuming that the skb is associated with an Ethernet
device or checking only that the `ETH_HLEN` bytes at
`skb_mac_header(skb)` lie between `skb->head` and `skb->data`.
Make these paths first verify that the skb is associated with an
Ethernet device, that the MAC header was set, and that it spans at
least a full Ethernet header before accessing `eth_hdr(skb)`.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| linux | linux | — | — |
| linux | linux | >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 4435888e1bf139d2bfe5911643d4217382136743 | 4435888e1bf139d2bfe5911643d4217382136743 |
| linux | linux | >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 063f43361e884acd7300790e90194430275d0d0c | 063f43361e884acd7300790e90194430275d0d0c |
| linux | linux | >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 726abf97566867f808fec9d8a408eb9698bd570a | 726abf97566867f808fec9d8a408eb9698bd570a |
| linux | linux | >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 367abcacc13a8e2e7624408b7f593bd1e60e49d9 | 367abcacc13a8e2e7624408b7f593bd1e60e49d9 |
| linux | linux | >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 5d634afb8b83b49de562792fd0d047416a43bd4d | 5d634afb8b83b49de562792fd0d047416a43bd4d |
| linux | linux | >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < cea435ea7e868ea6fdf039bc4f2090c1d829b556 | cea435ea7e868ea6fdf039bc4f2090c1d829b556 |
| linux | linux | >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 62443dc21114c0bbc476fa62973db89743f2f137 | 62443dc21114c0bbc476fa62973db89743f2f137 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 2.6.12.1 < 5.15.210 | 5.15.210 |
| linux | linux_kernel | >= 5.16 < 6.1.176 | 6.1.176 |
| linux | linux_kernel | >= 6.13 < 6.18.36 | 6.18.36 |
| linux | linux_kernel | >= 6.19 < 7.0.13 | 7.0.13 |
| linux | linux_kernel | >= 6.2 < 6.6.143 | 6.6.143 |
| linux | linux_kernel | >= 6.7 < 6.12.94 | 6.12.94 |
CVSS provenance
nvdv3.19.4CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H
vendor_redhat7.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
In the Linux kernel, the following vulnerability has been resolved: netfilter: require Ethernet MAC header before using eth_hdr() `ip6t_eui64`, `xt_mac`, the `bitmap:ip,mac`, `hash:ip,mac`, and `has
ghsa_unreviewed·2026-06-25
CVE-2026-53131 In the Linux kernel, the following vulnerability has been resolved: netfilter: require Ethernet MAC header before using eth_hdr() `ip6t_eui64`, `xt_mac`, the `bitmap:ip,mac`, `hash:ip,mac`, and `has
In the Linux kernel, the following vulnerability has been resolved:
netfilter: require Ethernet MAC header before using eth_hdr()
`ip6t_eui64`, `xt_mac`, the `bitmap:ip,mac`, `hash:ip,mac`, and
`hash:mac` ipset types, and `nf_log_syslog` access `eth_hdr(skb)`
after either assuming that the skb is associated with an Ethernet
device or checking only that the `ETH_HLEN` bytes at
`skb_mac_header(skb)` lie between `skb->head` and `skb->data`.
Make these paths first verify that the skb is associated with an
Ethernet device, that the MAC header was set, and that it spans at
least a full Ethernet header before accessing `eth_hdr(skb)`.
Red Hat
kernel: netfilter: require Ethernet MAC header before using eth_hdr()
vendor_redhat·2026-06-25·CVSS 7.0
CVE-2026-53131 [MEDIUM] CWE-125 kernel: netfilter: require Ethernet MAC header before using eth_hdr()
kernel: netfilter: require Ethernet MAC header before using eth_hdr()
A flaw was found in the Linux kernel's netfilter component. Certain netfilter modules, including `ip6t_eui64` and `xt_mac`, accessed Ethernet MAC header data without first verifying that an Ethernet device was associated with the network packet or that the MAC header was present and of sufficient length. This oversight could allow a local or remote attacker to trigger an out-of-bounds read, potentially leading to a system crash and a Denial of Service (DoS).
Package: kernel (Red Hat Enterprise Linux 10) - Affected
Package: kernel (Red Hat Enterprise Linux 6) - Out of support scope
Package: kernel (Red Hat Enterprise Linux 7) - Affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Affected
Package: kernel (Red
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/063f43361e884acd7300790e90194430275d0d0chttps://git.kernel.org/stable/c/367abcacc13a8e2e7624408b7f593bd1e60e49d9https://git.kernel.org/stable/c/4435888e1bf139d2bfe5911643d4217382136743https://git.kernel.org/stable/c/5d634afb8b83b49de562792fd0d047416a43bd4dhttps://git.kernel.org/stable/c/62443dc21114c0bbc476fa62973db89743f2f137https://git.kernel.org/stable/c/726abf97566867f808fec9d8a408eb9698bd570ahttps://git.kernel.org/stable/c/cea435ea7e868ea6fdf039bc4f2090c1d829b556
2026-06-25
Published