Junglewise Threat Intelligence

CVE-2026-63914: Linux Kernel information disclosure in XFRM MIGRATE notifications

CVE-2026-63914 · Severity: info · Published 2026-07-19

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's networking subsystem could allow a system administrator or a process in the main network environment to monitor secure connection migration events from other isolated network containers (namespaces). This occurs because the kernel incorrectly broadcasts certain IPsec (XFRM) migration notifications to the global network namespace instead of keeping them within the specific container where they originated. While this primarily impacts the reliability of secure connections within containers, it also results in a minor information leak where sensitive network endpoint details are exposed to unauthorized listeners on the host system.

Technical details

A vulnerability exists in net/xfrm/xfrm_user.c and net/key/af_key.c where xfrm_send_migrate() and pfkey_send_migrate() hardcode the '&init_net' namespace for multicast notifications. This causes XFRM_MSG_MIGRATE and SADB_X_MIGRATE events to be delivered to listeners in the initial network namespace regardless of their actual origin. Consequently, an IKE daemon in the root namespace can observe migration selectors and endpoint addresses from other namespaces (information leak), while daemons within non-init namespaces fail to receive their own migration updates, breaking IKEv2 MOBIKE support. The fix involves threading the 'struct net' context through km_migrate() and the xfrm_mgr.migrate function pointer to ensure namespace-aware broadcasting.

Affected products

  • Linux Linux Kernel v5.15+

Timeline

  • 2026-05-04: disclosed: Initial patch authored
  • 2026-06-19: patched: Patch committed to stable tree
  • 2026-07-19: advisory: CVE published

References

Related threats