Answer in brief
CVE-2026-53134 records a Medium severity (CVSS 5.5) vulnerability in netfilter: nft_fib: fix stale stack leak via the OIFNAME register. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic), Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (generic), Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 5.5. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic), Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (generic), Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=f6d0cbcf09c506b9b022df8f9d7693a7cec3c732 <6744e49fe51bfba26522acc2d0e9703cb41d8e50 || >=f6d0cbcf09c506b9b022df8f9d7693a7cec3c732 <eca18feed38b3377a2ec5d1f22af1170c55d0171 || >=f6d0cbcf09c506b9b022df8f9d7693a7cec3c732 <d19ddef8c327a4773ff81f8e51027d1e0b4cf069 || >=f6d0cbcf09c506b9b022df8f9d7693a7cec3c732 <eb8a8124484dbc3c2b543e207da39bbccb703d31 || >=f6d0cbcf09c506b9b022df8f9d7693a7cec3c732 <8c84885e9790823828bb8084736ea15769b1ac16 || >=f6d0cbcf09c506b9b022df8f9d7693a7cec3c732 <84d8f58cf28a0415413f43ba7148f7bacd4c1b6e || >=f6d0cbcf09c506b9b022df8f9d7693a7cec3c732 <3544210609f6d1db282bbdeca639104ef624c393 || >=f6d0cbcf09c506b9b022df8f9d7693a7cec3c732 <ab185e0c4fb82dfba6fb86f8271e06f931d9c64c | 6744e49fe51bfba26522acc2d0e9703cb41d8e50, eca18feed38b3377a2ec5d1f22af1170c55d0171, d19ddef8c327a4773ff81f8e51027d1e0b4cf069, eb8a8124484dbc3c2b543e207da39bbccb703d31, 8c84885e9790823828bb8084736ea15769b1ac16, 84d8f58cf28a0415413f43ba7148f7bacd4c1b6e, 3544210609f6d1db282bbdeca639104ef624c393, ab185e0c4fb82dfba6fb86f8271e06f931d9c64c |
| Linux/Linuxgeneric | 4.10 | Not reported |
| Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFPgeneric | >=V3.1.6 <* | * |
| Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFPgeneric | >=V3.1.6 <* | * |
| Siemens/SIPLUS S7-1500 CPU 1518-4 PN/DP MFPgeneric | >=V3.1.6 <* | * |
Published upstream
Jun 25, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 8, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Jun 25, 2026
In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_fib: fix stale stack leak via the OIFNAME register For NFT_FIB_RESULT_OIFNAME the destination register is declared with len = IFNAMSIZ (four 32-bit registers), but on the lookup-fail, RTN_LOCAL and oif-mismatch paths nft_fib{4,6}_eval() only writes one register via "*dest = 0". The remaining three registers are left as whatever was on the stack in nft_do_chain()'s struct nft_regs, and a downstream expression that loads the register span can leak that uninitialised kernel stack to userspace. The NFTA_FIB_F_PRESENT existence check has the same shape: it is only meaningful for NFT_FIB_RESULT_OIF, yet it was accepted for any result type while the eval stores a single byte via nft_reg_store8(), leaving the rest of the declared span stale. Fix both: - replace the bare "*dest = 0" in the eval with nft_fib_store_result(), which strscpy_pad()s the whole IFNAMSIZ for OIFNAME (and is already used on the other early-return path), and - restrict NFTA_FIB_F_PRESENT to NFT_FIB_RESULT_OIF and declare its destination as a single u8, so the marked span matches the one byte the eval writes.
Quoted source text, attributed separately from HOL analysis.