Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_meta_bridge: fix stale stack leak via IIFHWADDR register NFT_META_BRI_IIFHWADDR declares its destination register with len = ETH_ALEN (6 bytes), which the register-init tracking rounds up to two 32-bit registers (8 bytes). nft_meta_bridge_get_eval() then does memcpy(dest, br_dev->dev_addr, ETH_ALEN), writing only 6 bytes and leaving the upper 2 bytes of the second register as uninitialised nft_do_chain() stack. A downstream load of that register span leaks those stale bytes to userspace. Zero the second register before the memcpy so the full declared span is written.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 6.18, < 6.18.36 |
Related Weaknesses (CWE)
References
- https://git.kernel.org/stable/c/07acb9798477535933bd658ac9fa85b6cb10d995Patch
- https://git.kernel.org/stable/c/c7d573551f9286100a055ef696cde6af54549677Patch
- https://git.kernel.org/stable/c/f1e81d571e375d10e50e852223593493d98c1bacPatch
FAQ
What is CVE-2026-53211?
CVE-2026-53211 is a vulnerability with a CVSS score of 5.5 (MEDIUM). In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_meta_bridge: fix stale stack leak via IIFHWADDR register NFT_META_BRI_IIFHWADDR declares its destination register w...
How severe is CVE-2026-53211?
CVE-2026-53211 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-53211?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.