SB20260720319 - Improper access control in Linux kernel xfrm
Published: July 20, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper access control (CVE-ID: CVE-2026-63914)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to improper access control in xfrm migrate notification handling in net/xfrm/xfrm_user.c and net/key/af_key.c when broadcasting successful XFRM_MSG_MIGRATE or SADB_X_MIGRATE events across network namespaces. A local user can trigger a migration notification from a non-init network namespace to disclose sensitive information.
An IKE daemon running in the initial network namespace may receive migration notifications originating from other network namespaces, including selector, old and new endpoint addresses, and the km_address.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/00f2c451e57df50b1151d9b2254878f106b7c892
- https://git.kernel.org/stable/c/26ce8dbf2e23fe4fcc3351d19ef6d3fb703ed126
- https://git.kernel.org/stable/c/448bb92ca101dde8a6e88b4dc824044b4e341604
- https://git.kernel.org/stable/c/6df8157547347b5257bf640a0ae3dfc4411e06cd
- https://git.kernel.org/stable/c/7e2a4f7ca0952820731ef7bdadfc9a9e9d3571b4
- https://git.kernel.org/stable/c/a306cf2ac8849c487791369fad6f216399d000f6
- https://git.kernel.org/stable/c/bafc7d0774b9bf52909c70ed990bc5ccf7ec4bad
- https://git.kernel.org/stable/c/fe463798343382c8fe9416a95959f005a3c30aa5