CVE-2026-64436

Source
https://cve.org/CVERecord?id=CVE-2026-64436
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64436.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-64436
Downstream
Related
Published
2026-07-25T08:51:10.370Z
Modified
2026-08-18T03:31:22.370053358Z
Severity
  • 7.1 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H CVSS Calculator
Summary
net: af_key: initialize alg_key_len for IPComp states
Details

In the Linux kernel, the following vulnerability has been resolved:

net: afkey: initialize algkey_len for IPComp states

pfkeymsg2xfrmstate() handles the IPComp (SADBXSATYPE_IPCOMP) case by allocating x->calg and copying only the algorithm name:

x->calg = kmalloc_obj(*x->calg);
if (!x->calg) {
    err = -ENOMEM;
    goto out;
}
strcpy(x->calg->alg_name, a->name);
x->props.calgo = sa->sadb_sa_encrypt;

Unlike the authentication (x->aalg) and encryption (x->ealg) branches of the same function, the compression branch never initializes calg->algkeylen. IPComp carries no key and the allocation only reserves sizeof(struct xfrm_algo) (i.e. no room for a key), so the field is left containing uninitialized slab data.

calg->algkeylen is later used as a length by xfrmalgoclone() when an IPComp state is cloned during XFRMMSGMIGRATE:

xfrm_state_migrate()
  xfrm_state_clone_and_setup()
    x->calg = xfrm_algo_clone(orig->calg);
      kmemdup(orig, xfrm_alg_len(orig));

where xfrmalglen() returns sizeof(*alg) + (algkeylen + 7) / 8. With a non-zero garbage algkeylen, kmemdup() reads past the end of the 68-byte calg object. Adding an IPComp SA via PFKEY and then migrating it triggers (net-next, KASAN, initon_alloc=0):

BUG: KASAN: slab-out-of-bounds in kmemdupnoprof+0x44/0x60 Read of size 4164 at addr ff11000025a74980 by task diag2/9287 CPU: 3 UID: 0 PID: 9287 Comm: diag2 7.1.0-rc6-g903db046d557 #1 Call Trace: <TASK> dumpstacklvl+0x10e/0x1f0 printreport+0xf7/0x600 kasanreport+0xe4/0x120 kasancheck_range+0x105/0x1b0 __asanmemcpy+0x23/0x60 kmemdupnoprof+0x44/0x60 xfrmstatemigrate+0x70a/0x1da0 xfrmmigrate+0x753/0x18a0 xfrmdomigrate+0xb47/0xf10 xfrmuserrcvmsg+0x411/0xb50 netlinkrcvskb+0x158/0x420 xfrmnetlinkrcv+0x71/0x90 netlinkunicast+0x584/0x850 netlinksendmsg+0x8b0/0xdc0 ____sys_sendmsg+0x9f7/0xb90 ___sys_sendmsg+0x134/0x1d0 _syssendmsg+0x16d/0x220 dosyscall64+0x116/0x7d0 entrySYSCALL64afterhwframe+0x77/0x7f </TASK>

Allocated by task 9287: kasansavestack+0x33/0x60 kasansavetrack+0x14/0x30 __kasankmalloc+0xaa/0xb0 pfkeyadd+0x2652/0x2ea0 pfkeyprocess+0x6d0/0x830 pfkeysendmsg+0x42c/0x850 __sys_sendto+0x461/0x4b0 __x64syssendto+0xe0/0x1c0 dosyscall64+0x116/0x7d0 entrySYSCALL64afterhwframe+0x77/0x7f

The buggy address belongs to the object at ff11000025a74980 which belongs to the cache kmalloc-96 of size 96 The buggy address is located 0 bytes inside of allocated 68-byte region [ff11000025a74980, ff11000025a749c4)

Depending on the uninitialized value the same field can instead request an oversized kmemdup() allocation and make the migration clone fail.

The XFRM netlink path is not affected: verifyonealg() rejects an XFRMAALGCOMP attribute shorter than xfrmalglen(), so a calg added via XFRMMSGNEWSA is always self-consistent.

Initialize calg->algkeylen to 0, matching the aalg/ealg branches.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64436.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
80c9abaabf4283f7cf4a0b3597cd302506635b7f
Fixed
58e82fc3dedb57b1432292504415b224fd2d6acb
Fixed
01b9115b55018123ef2449ac4951f89147a8428e
Fixed
3f63d1752d90c0e28be931a48ab5d89bc97d637d
Fixed
273c06b81d2e902b21acc801ae18c8276c8a9b69
Fixed
6de2a650917bedaaefd65b17cede83c5e2c1dedd
Fixed
e8417353cbd078d10531ba3928e609c84ab09e6b
Fixed
cea34abc94b0a81e3a8b5cfb41cf45af37c2c67e
Fixed
d129c3177d7b1138fd5066fcc63a698b3ba415b0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64436.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.6.21
Fixed
5.10.261
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.212
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.178
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.145
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.96
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.39
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64436.json"