Out-of-bounds read in Linux kernel - CVE-2026-52942
Published: June 25, 2026
Vulnerability details
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in dump_mac_header() in the netfilter nf_log syslog logger when processing an skb sent through AF_PACKET with PACKET_QDISC_BYPASS and an unset MAC header. A local user can send a specially crafted packet to disclose sensitive information.
Only skbs with an unset MAC header are affected.
Affected software
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Real Time
Red Hat Enterprise Linux for Real Time for NFV
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
openEuler
Ubuntu
kernel (Red Hat package)
kernel-rt (Red Hat package)
kernel-debuginfo
bpftool-debuginfo
bpftool
kernel
kernel-debugsource
kernel-devel
kernel-source
kernel-tools
kernel-tools-debuginfo
kernel-tools-devel
perf
perf-debuginfo
python2-perf
python2-perf-debuginfo
python3-perf
python3-perf-debuginfo
kernel-headers
linux (Ubuntu package)
linux-azure (Ubuntu package)
linux-oracle-7.0 (Ubuntu package)
linux-gcp-7.0 (Ubuntu package)
linux-oem-7.0 (Ubuntu package)
linux-ibm (Ubuntu package)
linux-azure-7.0 (Ubuntu package)
linux-nvidia (Ubuntu package)
linux-nvidia-7.0 (Ubuntu package)
linux-raspi (Ubuntu package)
linux-nvidia-bos (Ubuntu package)
How to mitigate CVE-2026-52942
kernel (Red Hat package) - update to 4.18.0-553.162.1.el8_10
kernel-rt (Red Hat package) - update to 4.18.0-553.162.1.rt7.503.el8_10
kernel-debuginfo - addressed in versions 4.19.90-2608.2.0.0384, 5.10.0-326.0.0.227
bpftool-debuginfo - addressed in versions 4.19.90-2608.2.0.0384, 5.10.0-326.0.0.227
bpftool - addressed in versions 4.19.90-2608.2.0.0384, 5.10.0-326.0.0.227
kernel - addressed in versions 4.19.90-2608.2.0.0384, 5.10.0-326.0.0.227
kernel-debugsource - addressed in versions 4.19.90-2608.2.0.0384, 5.10.0-326.0.0.227
kernel-devel - addressed in versions 4.19.90-2608.2.0.0384, 5.10.0-326.0.0.227
kernel-source - addressed in versions 4.19.90-2608.2.0.0384, 5.10.0-326.0.0.227
kernel-tools - addressed in versions 4.19.90-2608.2.0.0384, 5.10.0-326.0.0.227
kernel-tools-debuginfo - addressed in versions 4.19.90-2608.2.0.0384, 5.10.0-326.0.0.227
kernel-tools-devel - addressed in versions 4.19.90-2608.2.0.0384, 5.10.0-326.0.0.227
perf - addressed in versions 4.19.90-2608.2.0.0384, 5.10.0-326.0.0.227
perf-debuginfo - addressed in versions 4.19.90-2608.2.0.0384, 5.10.0-326.0.0.227
python2-perf - update to 4.19.90-2608.2.0.0384
python2-perf-debuginfo - update to 4.19.90-2608.2.0.0384
python3-perf - addressed in versions 4.19.90-2608.2.0.0384, 5.10.0-326.0.0.227
python3-perf-debuginfo - addressed in versions 4.19.90-2608.2.0.0384, 5.10.0-326.0.0.227
kernel-headers - update to 5.10.0-326.0.0.227
linux (Ubuntu package) - addressed in versions 7.0.0-31.31, 7.0.0-31.31.1, 7.0.0-31.31~24.04.1, 7.0.0-1006.7, 7.0.0-1011.11~24.04.1, 7.0.0-1012.12, 7.0.0-1012.12~24.04.1
linux-azure (Ubuntu package) - addressed in versions 7.0.0-1011.11, 7.0.0-1014.14
linux-oracle-7.0 (Ubuntu package) - update to 7.0.0-1011.11~24.04.1
linux-gcp-7.0 (Ubuntu package) - update to 7.0.0-1011.11~24.04.1
linux-oem-7.0 (Ubuntu package) - update to 7.0.0-1013.13
linux-ibm (Ubuntu package) - update to 7.0.0-1013.13
linux-azure-7.0 (Ubuntu package) - update to 7.0.0-1014.14~24.04.1
linux-nvidia (Ubuntu package) - update to 7.0.0-1018.18
linux-nvidia-7.0 (Ubuntu package) - update to 7.0.0-1018.18~24.04.1
linux-raspi (Ubuntu package) - update to 7.0.0-1019.19
linux-nvidia-bos (Ubuntu package) - update to 7.0.0-2018.18
External References
- https://git.kernel.org/stable/c/65ef7397eb9a296e91839f5fd10be96f23d332e7
- https://git.kernel.org/stable/c/8a81e336da685423f5b64aac4d571e63d674c52a
- https://git.kernel.org/stable/c/a84b6fedbc97078788be78dbdd7517d143ad1a77
- https://git.kernel.org/stable/c/af1b7699466f6556b351fa25d3dc870abfb5d310
- https://git.kernel.org/stable/c/befb8968a2abdfa948d5600ea7f7a509a292a590
- https://git.kernel.org/stable/c/c38d41134085193efd5b237cf513ad5b3421a60d
- https://git.kernel.org/stable/c/d704ee9c7bc68a161684c51a7ac05b446dcf38d4
Related Security Bulletins
- Out-of-bounds read in Linux kernel netfilter
- openEuler 22.03 LTS SP4 update for kernel
- openEuler 20.03 LTS SP4 update for kernel
- Ubuntu update for linux-oem-7.0
- Ubuntu update for linux
- Ubuntu update for linux-gcp-7.0
- Red Hat Enterprise Linux 8 update for kernel-rt
- Red Hat Enterprise Linux 8 update for kernel
- Ubuntu update for linux-oracle-7.0
- Ubuntu update for linux-azure
- Ubuntu update for linux-azure-7.0
- Ubuntu update for linux-nvidia
- Ubuntu update for linux-nvidia-bos
- Ubuntu update for linux-ibm
- Ubuntu update for linux-raspi
- Ubuntu update for linux-nvidia-7.0