CVE-2026-64076: netfilter: bridge: eb_tables: close module init race
In the Linux kernel, the following vulnerability has been resolved:
netfilter: bridge: ebtables: close module init race
sashiko reports for unrelated patch: Does the core ebtables initialization in ebtables.c suffer from a similar race? Once nfregistersockopt() completes, the sockopts are exposed globally.
sockopt has to be registered last, just like in ip/ip6/arptables.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Register the ebtables sockopts last during module initialization, after other initialization completes, so they are not globally exposed prematurely.
Linux kernel netfilter bridge ebtables nf_register_sockopt() registration order = last
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The CVSS vector indicates local access and low privileges are required. No user interaction is required.
What security impact could successful exploitation have?
The CVSS vector rates confidentiality, integrity, and availability impacts as high. The vulnerability is scoped to the vulnerable system.
What is the immediate remediation?
Apply an available patch for the Linux kernel. The supplied stable kernel references identify patches for this issue.