Answer in brief
CVE-2026-64412 records a Unknown severity vulnerability in netfilter: ebtables: module names must be null-terminated. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2026-64412 records a Unknown severity vulnerability in netfilter: ebtables: module names must be null-terminated. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=bcf4934288402be3464110109a4dae3bd6fb3e93 <43dd2332b8a27b3ac5108791680cade654ab0f96 || >=bcf4934288402be3464110109a4dae3bd6fb3e93 <5777c8f1c3610786d8482b8f620f40fccaf1542b || >=bcf4934288402be3464110109a4dae3bd6fb3e93 <0ddca0f90fa3395111d078ae4399615cf3ea94aa || >=bcf4934288402be3464110109a4dae3bd6fb3e93 <d2367d99f2455f373996d9ddbe833dbe9f942213 || >=bcf4934288402be3464110109a4dae3bd6fb3e93 <da32e78bbb187ed7b137e0007034185570a3a172 || >=bcf4934288402be3464110109a4dae3bd6fb3e93 <13a5f532e3a4fc75c33060a026def1572c208643 || >=bcf4934288402be3464110109a4dae3bd6fb3e93 <7b217960e88b5d2d1e8cdcbcaf3bdf6fe199a0c8 || >=bcf4934288402be3464110109a4dae3bd6fb3e93 <084d23f818321390509e9738a0b08bbf46df6425 | 43dd2332b8a27b3ac5108791680cade654ab0f96, 5777c8f1c3610786d8482b8f620f40fccaf1542b, 0ddca0f90fa3395111d078ae4399615cf3ea94aa, d2367d99f2455f373996d9ddbe833dbe9f942213, da32e78bbb187ed7b137e0007034185570a3a172, 13a5f532e3a4fc75c33060a026def1572c208643, 7b217960e88b5d2d1e8cdcbcaf3bdf6fe199a0c8, 084d23f818321390509e9738a0b08bbf46df6425 |
| Linux/Linuxgeneric | 4.6 | Not reported |
Published upstream
Jul 25, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: netfilter: ebtables: module names must be null-terminated We need to explicitly check the length, else we may pass non-null terminated string to request_module().
Quoted source text, attributed separately from HOL analysis.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=bcf4934288402be3464110109a4dae3bd6fb3e93 <43dd2332b8a27b3ac5108791680cade654ab0f96 || >=bcf4934288402be3464110109a4dae3bd6fb3e93 <5777c8f1c3610786d8482b8f620f40fccaf1542b || >=bcf4934288402be3464110109a4dae3bd6fb3e93 <0ddca0f90fa3395111d078ae4399615cf3ea94aa || >=bcf4934288402be3464110109a4dae3bd6fb3e93 <d2367d99f2455f373996d9ddbe833dbe9f942213 || >=bcf4934288402be3464110109a4dae3bd6fb3e93 <da32e78bbb187ed7b137e0007034185570a3a172 || >=bcf4934288402be3464110109a4dae3bd6fb3e93 <13a5f532e3a4fc75c33060a026def1572c208643 || >=bcf4934288402be3464110109a4dae3bd6fb3e93 <7b217960e88b5d2d1e8cdcbcaf3bdf6fe199a0c8 || >=bcf4934288402be3464110109a4dae3bd6fb3e93 <084d23f818321390509e9738a0b08bbf46df6425 | 43dd2332b8a27b3ac5108791680cade654ab0f96, 5777c8f1c3610786d8482b8f620f40fccaf1542b, 0ddca0f90fa3395111d078ae4399615cf3ea94aa, d2367d99f2455f373996d9ddbe833dbe9f942213, da32e78bbb187ed7b137e0007034185570a3a172, 13a5f532e3a4fc75c33060a026def1572c208643, 7b217960e88b5d2d1e8cdcbcaf3bdf6fe199a0c8, 084d23f818321390509e9738a0b08bbf46df6425 |
| Linux/Linuxgeneric | 4.6 | Not reported |
Published upstream
Jul 25, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: netfilter: ebtables: module names must be null-terminated We need to explicitly check the length, else we may pass non-null terminated string to request_module().
Quoted source text, attributed separately from HOL analysis.