Junglewise Threat Intelligence

CVE-2026-64414: Linux Kernel Netfilter improper handling of unreadable fragments

CVE-2026-64414 · Severity: info · CVSS 5.3 · Published 2026-07-25

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's Netfilter component, which handles network traffic filtering and logging. Under specific conditions involving specialized network data (devmem TCP), the system could incorrectly process unreadable data fragments. This could lead to unexpected system behavior or minor service disruptions in network logging and queueing functions.

Technical details

A vulnerability in the Linux kernel Netfilter subsystem arises when processing socket buffers (skbs) with unreadable fragments, such as those generated by devmem TCP. In affected versions, the 'xt_u32' module and 'nfnetlink' logging/queueing components do not check the readability of fragments before attempting to access them via 'skb_copy_bits()'. This can trigger a BUG() or return unhandled error codes. The fix introduces checks for 'skb_frags_readable()' and ensures that 'xt_u32' bails out with a 'hotdrop' and that nfnetlink restricts operations to the linear part of the buffer. Patches have been released for various stable branches including 6.12.y, 6.18.y, and 7.1.y.

Affected products

  • Linux Linux Kernel 6.12, 6.18, 7.1, 7.2-rc3

Timeline

  • 2026-07-05: other: Vulnerability fixed in upstream kernel source
  • 2026-07-25: disclosed: CVE-2026-64414 published

References

Related threats