CVE-2026-53131: netfilter: require Ethernet MAC header before using eth_hdr()
In the Linux kernel, the following vulnerability has been resolved:
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.1.176-1Fixed in 6.1.180-1Fixed in 6.12.94-1Fixed in 6.12.107-1Fixed in 7.1.12-1Fixed in 7.1.13-1 - Configuration
Apply the Linux kernel fix so netfilter requires an skb to be associated with an Ethernet device, with the MAC header set and spanning at least a full Ethernet header, before calling eth_hdr(skb). This addresses netfilter: require Ethernet MAC header before using eth_hdr().
Linux kernel netfilter netfilter: require Ethernet MAC header before using eth_hdr() = enabled/required
Event History
Frequently Asked Questions
What is the severity of CVE-2026-53131?
CVE-2026-53131 has a critical severity score of 9.4.
How do I fix CVE-2026-53131?
To fix CVE-2026-53131, apply the available patches for the Linux kernel.
What systems are affected by CVE-2026-53131?
CVE-2026-53131 affects the Linux kernel and Microsoft azl3 kernel version 6.6.143.1-1.
What does CVE-2026-53131 exploit?
CVE-2026-53131 exploits a failure to require an Ethernet MAC header before using eth_hdr() in netfilter.
When was CVE-2026-53131 published?
CVE-2026-53131 was published on June 25, 2026.