Out-of-bounds read in Linux kernel - CVE-2026-53238
Published: June 26, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in netlbl_unlabel_addrinfo_get() when handling crafted Generic Netlink requests with a shorter unlabeled address mask attribute. A local user can send a specially crafted Generic Netlink request to cause a denial of service.
How to mitigate CVE-2026-53238
Sources
- https://git.kernel.org/stable/c/07a18f5c90dd3d586b73242f5a5bbf0a72f2fdc6
- https://git.kernel.org/stable/c/0c4bb32ad7fdc2dc6a8050f41eb04d4bda56b6c8
- https://git.kernel.org/stable/c/672f0f3b8f875ffe6525a37847eafa7648c4c0c6
- https://git.kernel.org/stable/c/71c52da13c3737493b42d20d9f33de34e03b3156
- https://git.kernel.org/stable/c/95bda3eac0b1454c2cee98d58d9ba6dd8391e843
- https://git.kernel.org/stable/c/975a84fd741440853380d37465b6e226cf47254c
- https://git.kernel.org/stable/c/9772589b57e44aedc240211c5c3f7a684a034d3a
- https://git.kernel.org/stable/c/ccfe292a966079c61ea68a2da303b2a336170993