CVE-2026-64553

Source
https://cve.org/CVERecord?id=CVE-2026-64553
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64553.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-64553
Downstream
Published
2026-07-27T20:10:41.159Z
Modified
2026-07-29T03:48:18.440425272Z
Summary
net: psample: fix info leak in PSAMPLE_ATTR_DATA
Details

In the Linux kernel, the following vulnerability has been resolved:

net: psample: fix info leak in PSAMPLEATTRDATA

psample open codes nlaput() presumably to avoid wiping the data with 0s just to override it with packet data. This open coding is missing clearing the pad, however, each netlink attr is padded to 4B and datalen may not be divisible by 4B.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64553.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
6ae0a6286171154661b74f7f550f9441c6008424
Fixed
0d3ea2ccddda442077fc44f11d873209c97ec50b
Fixed
7fe7e6949964aa8ee6305f09db2dc9eede977bb3
Fixed
e2fa322782a2d7d8078f7bb20817e0aa9f7c32e9
Fixed
befe1ebe7fc2c65c80074bc34ceeb0a721ed3cd2
Fixed
48930f6c59fd0056c2de46ce52bfe27d9c9e5eb6
Fixed
a6cfb924ad74efce254e99c197d2e3863de70868
Fixed
794a0d8bdbb39e083ed42caccb86d687a9b53570
Fixed
aedd02af1f8b0bceb7f42f5a21c41634ca9ed390

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64553.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.11.0
Fixed
5.10.261
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.212
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.178
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.145
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.97
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.40
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64553.json"