{"id":"CVE-2026-53013","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nmacvlan: fix macvlan_get_size() not reserving space for IFLA_MACVLAN_BC_CUTOFF\n\nmacvlan_get_size() does not account for IFLA_MACVLAN_BC_CUTOFF, but\nmacvlan_fill_info() …","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nmacvlan: fix macvlan_get_size() not reserving space for IFLA_MACVLAN_BC_CUTOFF\n\nmacvlan_get_size() does not account for IFLA_MACVLAN_BC_CUTOFF, but\nmacvlan_fill_info() …","severity":"none","published":"2026-06-24","updated":"2026-07-10","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-53013","references":[{"url":"https://git.kernel.org/stable/c/1c004f14ccdc11585625c168bb9a7c5e1b8afb0c","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4979252758387b338ca968ba7e0515b0ae2257e3","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/77ecfa4e27f282d224215895ddfbeb916fc75e24","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b6b7154e9f5d75b608ceb2d05b376de8c638c40e","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fa92a77b0ed4d5f11a71665a232ac5a54a4b055d","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd"],"epss":0.00122,"epssPercentile":0.02296,"ingestedAt":"2026-07-11T19:15:11.742Z","slug":"CVE-2026-53013","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nmacvlan: fix macvlan_get_size() not reserving space for IFLA_MACVLAN_BC_CUTOFF\n\nmacvlan_get_size() does not account for IFLA_MACVLAN_BC_CUTOFF, but\nmacvlan_fill_info() conditionally includes it when port->bc_cutoff != 1.\nThis causes nla_put_s32() to fail with -EMSGSIZE when the netlink skb\nruns out of space, triggering a WARN_ON in rtnetlink and preventing the\ninterface from being dumped.\n\nThe bug can be reproduced with:\n\n  ip link add macvlan0 link eth0 type macvlan mode bridge\n  ip link set macvlan0 type macvlan bc_cutoff 0\n  ip -d link show macvlan0   # fails with -EMSGSIZE\n\nThe bc_cutoff feature was added in commit 954d1fa1ac93 (\"macvlan: Add\nnetlink attribute for broadcast cutoff\"), which added the nla_put_s32()\ncall in macvlan_fill_info() but missed adding the corresponding\nnla_total_size(4) in macvlan_get_size(). A follow-up commit\n55cef78c244d (\"macvlan: add forgotten nla_policy for\nIFLA_MACVLAN_BC_CUTOFF\") fixed the missing nla_policy entry but still\ndid not fix the size calculation.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}