Junglewise Threat Intelligence

CVE-2026-64114: Linux Kernel out-of-bounds access in IPv4 raw socket handling

CVE-2026-64114 · Severity: info · CVSS 6.2 · Published 2026-07-19

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's networking component could allow a local user to crash the system. By sending specially crafted network packets that contain invalid header information, an attacker can trigger a kernel panic, leading to a complete denial of service. This issue affects systems where users have permissions to create raw network sockets, which is common in certain containerized or administrative environments.

Technical details

A vulnerability exists in the raw_send_hdrinc() function in net/ipv4/raw.c where the kernel fails to reject IPv4 packets with an Internet Header Length (IHL) less than 5. When a malformed packet with ihl < 5 is processed, downstream consumers like ah_output() in net/ipv4/ah4.c perform calculations that result in a negative signed integer. When this value is cast to a size_t for a memcpy() operation, it results in an extremely large out-of-bounds access, causing a host kernel panic. The attack requires CAP_NET_RAW, which can be obtained by unprivileged processes in environments with user and network namespaces enabled (CONFIG_USER_NS=y). The issue has been resolved by adding a check to reject packets where iphlen is less than the size of the IPv4 header.

Affected products

  • Linux Linux Kernel Introduced in 2.6.12-rc2; fixed in various stable branches including 6.x, 5.x, 4.x

Timeline

  • 2026-05-12: disclosed: Initial patch submission by Michael Bommarito
  • 2026-06-01: patched: Patch committed to stable branches by Greg Kroah-Hartman
  • 2026-07-19: advisory: CVE-2026-64114 published

References

Related threats