---
id: CVE-2026-53013
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  macvlan: fix macvlan_get_size() not reserving space for IFLA_MACVLAN_BC_CUTOFF

  macvlan_get_size() does not account for IFLA_MACVLAN_BC_CUTOFF, but
  macvlan_fill_info() …
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  macvlan: fix macvlan_get_size() not reserving space for IFLA_MACVLAN_BC_CUTOFF

  macvlan_get_size() does not account for IFLA_MACVLAN_BC_CUTOFF, but
  macvlan_fill_info() …
severity: none
published: '2026-06-24'
updated: '2026-07-10'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-53013'
references:
  - url: 'https://git.kernel.org/stable/c/1c004f14ccdc11585625c168bb9a7c5e1b8afb0c'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/4979252758387b338ca968ba7e0515b0ae2257e3'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/77ecfa4e27f282d224215895ddfbeb916fc75e24'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/b6b7154e9f5d75b608ceb2d05b376de8c638c40e'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/fa92a77b0ed4d5f11a71665a232ac5a54a4b055d'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
epss: 0.00122
epssPercentile: 0.02276
ingestedAt: '2026-07-11T19:15:11.742Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

macvlan: fix macvlan_get_size() not reserving space for IFLA_MACVLAN_BC_CUTOFF

macvlan_get_size() does not account for IFLA_MACVLAN_BC_CUTOFF, but
macvlan_fill_info() conditionally includes it when port->bc_cutoff != 1.
This causes nla_put_s32() to fail with -EMSGSIZE when the netlink skb
runs out of space, triggering a WARN_ON in rtnetlink and preventing the
interface from being dumped.

The bug can be reproduced with:

  ip link add macvlan0 link eth0 type macvlan mode bridge
  ip link set macvlan0 type macvlan bc_cutoff 0
  ip -d link show macvlan0   # fails with -EMSGSIZE

The bc_cutoff feature was added in commit 954d1fa1ac93 ("macvlan: Add
netlink attribute for broadcast cutoff"), which added the nla_put_s32()
call in macvlan_fill_info() but missed adding the corresponding
nla_total_size(4) in macvlan_get_size(). A follow-up commit
55cef78c244d ("macvlan: add forgotten nla_policy for
IFLA_MACVLAN_BC_CUTOFF") fixed the missing nla_policy entry but still
did not fix the size calculation.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
