CVE-2026-64414

Source
https://cve.org/CVERecord?id=CVE-2026-64414
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64414.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-64414
Downstream
Published
2026-07-25T08:50:54.495Z
Modified
2026-07-28T04:03:05.452928379Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
netfilter: handle unreadable frags
Details

In the Linux kernel, the following vulnerability has been resolved:

netfilter: handle unreadable frags

sashiko reports: When an skb with unreadable fragments (such as from devmem TCP, where skbfragsreadable(skb) returns false) is processed by the u32 module, skbcopybits() will safely return a negative error code [..]

xtu32: bail out with hotdrop in this case. gatherfrags: return -1, just as if we had no fragment header. nfnetlinkqueue: restrict to the linear part. nfnetlinklog: restrict to the linear part.

v2: - skbzerocopy helpers don't copy readable flag, i.e. nfnetlinkqueue is broken too xt_u32 shouldn't return true if hotdrop was set.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64414.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
65249feb6b3df9e17bab5911ee56fa7b0971e231
Fixed
3b13e7635795394705920cca1e1db7e4ca2e334b
Fixed
fc5bfe63bacf8a3ae307b62b34206406ca733354
Fixed
57056be3ec12e7d9ecd20a60d4060f510e4f284c
Fixed
da5b58478a9c1b85608c9e40a3b8432d071b409e

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64414.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.12.0
Fixed
6.12.96
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.39
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64414.json"