---
cve: "CVE-2026-64413"
severity: "HIGH"
cvss: 7.0
epss: "12%"
vendor: "Linux"
kev: false
exploited: false
published: "2026-07-25 10:17:25"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-09-06T15:14:05+02:00"
---

# CVE-2026-64413

> 7.0 HIGH

## Beschreibung

In the Linux kernel, the following vulnerability has been resolved:

netfilter: ebtables: zero chainstack array

sashiko reports:
 looking at ebtables table
 translation, could a sparse cpu_possible_mask lead to an uninitialized pointer
 free?

 If cpu_possible_mask is sparse (for example, CPU 0 and CPU 2 are possible,
 but CPU 1 is not), the allocation loop skips CPU 1. If vmalloc_node() fails at
 CPU 2, the cleanup loop will blindly decrement and call vfree() on
 newinfo->chainstack[1].

Not a real-world bug, such allocation isn't expected to fail
in the first place.

## CVSS-Vektor

```
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Lokal | good |
| AC Komplexität | Hoch | good |
| PR Privilegien | Gering | warn |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Hoch | bad |
| A Verfügbarkeit | Hoch | bad |

## Patch verfügbar (OSV)

- Kernel ≥ 5.10.261
- Kernel ≥ 5.15.212
- Kernel ≥ 6.1.178
- Kernel ≥ 6.6.145
- Kernel ≥ 6.12.97
- Kernel ≥ 6.18.39
- Kernel ≥ 7.1.4

## Referenzen

- <https://git.kernel.org/stable/c/2ade612967e2cdfb9290ebcb773f302c82f311fa>
- <https://git.kernel.org/stable/c/42bef500d07b5769d916e9122a3e3fa3fd2245ef>
- <https://git.kernel.org/stable/c/fc7f105451044501a50cfd530cfa3b472c54acbc>
- <https://git.kernel.org/stable/c/9e6c5169db423e51dcc66a73fd15409c0d38e088>
- <https://git.kernel.org/stable/c/29bf41a9b59aff9f6197df58641a00037d567ca8>
- <https://git.kernel.org/stable/c/9f74d28e903fa4fdf82f870d0aeadddc8196e41c>
- <https://git.kernel.org/stable/c/5ee856e4208acafaaaf7b84824d39b78c21345d6>
- <https://git.kernel.org/stable/c/cbfe53599eebffd188938ab6774cc41794f6f9d5>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-64413) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
