Junglewise Threat Intelligence

CVE-2026-64009: Linux Kernel out-of-bounds write in xfrm_state_mtu

CVE-2026-64009 · Severity: info · CVSS 7.8 · Published 2026-07-19

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's networking component could allow a local user to crash the system or potentially execute unauthorized commands. The issue occurs when processing specific types of encrypted network traffic (IPsec ESP) under unusual configuration settings. By manipulating technical parameters like the Maximum Transmission Unit (MTU) and encryption keys, an attacker can trigger a massive memory corruption event, leading to a complete system failure.

Technical details

An integer underflow vulnerability exists in the xfrm_state_mtu() function within the Linux kernel's XFRM (IPsec) subsystem. When calculating the MTU for an ESP tunnel, the function performs unsigned arithmetic that can underflow if the overhead (header length, authentication size, and network adjustment) exceeds the provided MTU. This underflowed value is subsequently treated as a signed integer in esp_output(), resulting in a negative 'tfclen' value. When this negative value is passed to memset() as a size_t, it is sign-extended to a massive positive value, causing an out-of-bounds write of zeroes (approximately 16 exabytes). A local user can trigger this by installing a specific IPv4 ESP tunnel SA with a large authentication key and a small interface MTU. The fix introduces underflow checks in xfrm_state_mtu() to return an error state.

Affected products

  • Linux Linux Kernel c5c252389374 to 742b04d0550b

Timeline

  • 2026-05-13: other: Patch authored
  • 2026-06-19: patched: Patch committed to stable tree
  • 2026-07-19: disclosed: CVE published

References

Related threats