Back to overview

CVE-2026-53013

Description
In the Linux kernel, the following vulnerability has been resolved: macvlan: fix macvlan_get_size() not reserving space for IFLA_MACVLAN_BC_CUTOFF macvlan_get_size() does not account for IFLA_MACVLAN_BC_CUTOFF, but macvlan_fill_info() conditionally includes it when port->bc_cutoff != 1. This causes nla_put_s32() to fail with -EMSGSIZE when the netlink skb runs out of space, triggering a WARN_ON in rtnetlink and preventing the interface from being dumped. The bug can be reproduced with: ip link add macvlan0 link eth0 type macvlan mode bridge ip link set macvlan0 type macvlan bc_cutoff 0 ip -d link show macvlan0 # fails with -EMSGSIZE The bc_cutoff feature was added in commit 954d1fa1ac93 ("macvlan: Add netlink attribute for broadcast cutoff"), which added the nla_put_s32() call in macvlan_fill_info() but missed adding the corresponding nla_total_size(4) in macvlan_get_size(). A follow-up commit 55cef78c244d ("macvlan: add forgotten nla_policy for IFLA_MACVLAN_BC_CUTOFF") fixed the missing nla_policy entry but still did not fix the size calculation.

Metadata

CVE ID
CVE-2026-53013
State
PUBLISHED
Assigner
Linux
Reserved
2026-06-09 07:44 UTC
Published
2026-06-24 16:29 UTC
Last updated
2026-06-24 16:29 UTC
Vendor / Product
Linux / Linux
Sources
cve.org  ·  NVD

Severity & Metrics

No CVSS data available.

Affected products (2)
VendorProductPlatformVersions
Linux Linux 954d1fa1ac93aa8a66f7d9a9ba545cf7f020d348 < 4979252758387b338ca968ba7e0515b0ae2257e3, 954d1fa1ac93aa8a66f7d9a9ba545cf7f020d348 < 77ecfa4e27f282d224215895ddfbeb916fc75e24, 954d1fa1ac93aa8a66f7d9a9ba545cf7f020d348 < b6b7154e9f5d75b608ceb2d05b376de8c638c40e, 954d1fa1ac93aa8a66f7d9a9ba545cf7f020d348 < 1c004f14ccdc11585625c168bb9a7c5e1b8afb0c …
Linux Linux 6.4, 0 < 6.4, 6.6.141 ≤ 6.6.*, 6.12.91 ≤ 6.12.* …
Back to overview