← All CVEs

CVE-2026-53131

critical · 9.4

In the Linux kernel, the following vulnerability has been resolved: netfilter: require Ethernet MAC header before using eth_hdr() `ip6t_eui64`, `xt_mac`, the `bitmap:ip,mac`, `hash:ip,mac`, and `hash:mac` ipset types, and `nf_log_syslog` access `eth_hdr(skb)` after either assuming that the skb is associated with an Ethernet device or checking only that the `ETH_HLEN` bytes at `skb_mac_header(skb)` lie between `skb->head` and `skb->data`. Make these paths first verify that the skb is associated with an Ethernet device, that the MAC header was set, and that it spans at least a full Ethernet header before accessing `eth_hdr(skb)`.

9.4
CVSS
0.4%
EPSS (exploit prob.)
36th
EPSS percentile
2026-06-25
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H

Affected products

VendorProductAffected versions
linuxlinux_kernel>= 2.6.12.1, < 5.15.210
linuxlinux_kernel>= 5.16, < 6.1.176
linuxlinux_kernel>= 6.2, < 6.6.143
linuxlinux_kernel>= 6.7, < 6.12.94
linuxlinux_kernel>= 6.13, < 6.18.36
linuxlinux_kernel>= 6.19, < 7.0.13
linuxlinux_kernel2.6.12
linuxlinux_kernel2.6.12
linuxlinux_kernel2.6.12
linuxlinux_kernel2.6.12
linuxlinux_kernel2.6.12

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2026-53131