Skip to main content

Threats Tagged 'cve-2026-53219'

View all threats tagged with 'cve-2026-53219'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cve-2026-53219

Threats Tagged 'cve-2026-53219'

Click on any threat for detailed analysis and mitigation recommendations

A vulnerability in the Linux kernel's netfilter x_tables subsystem could leak internal percpu counter pointers to userspace under certain fault conditions. This occurs when a userspace buffer faults during copying of rule entry headers, potentially exposing kernel memory addresses. The issue affects the native and compat get-entries paths for IPv4, IPv6, and ARP. The vulnerability has a medium severity rating with a CVSS score of 5.5 and does not impact confidentiality or integrity but can cause availability issues.

Join the discussion

In the Linux kernel, the following vulnerability has been resolved: netfilter: x_tables: avoid leaking percpu counter pointers The native and compat get-entries paths copy the fixed rule entry header from the kernelized rule blob to userspace before overwriting the entry's counter fields with a sanitized counter snapshot. On SMP kernels, entry->counters.pcnt contains the percpu allocation address used by x_tables rule counters. A caller can provide a userspace buffer that faults during the initial fixed-header copy after pcnt has been copied but before the later sanitized counter copy runs. The syscall then returns -EFAULT while leaving the raw percpu pointer in userspace. Copy only the fixed entry prefix before counters from the kernelized rule blob, then copy the sanitized counter snapshot into the counter field. Apply this ordering to the IPv4, IPv6, and ARP native and compat get-entries implementations so a fault cannot expose the internal percpu counter pointer.

Join the discussion

Showing 1 to 2 of 2 results

Filters:Tag: cve-2026-53219
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses