Use of Uninitialized Variable in Linux kernel - CVE-2026-64436
Published: July 27, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to use of uninitialized memory in pfkey_msg2xfrm_state() when processing a PF_KEY IPComp state and migrating it. A local user can add a crafted IPComp security association via PF_KEY and trigger migration to cause a denial of service.
The issue affects the PF_KEY path for IPComp states; the XFRM netlink path is not affected.
How to mitigate CVE-2026-64436
Sources
- https://git.kernel.org/stable/c/01b9115b55018123ef2449ac4951f89147a8428e
- https://git.kernel.org/stable/c/273c06b81d2e902b21acc801ae18c8276c8a9b69
- https://git.kernel.org/stable/c/3f63d1752d90c0e28be931a48ab5d89bc97d637d
- https://git.kernel.org/stable/c/58e82fc3dedb57b1432292504415b224fd2d6acb
- https://git.kernel.org/stable/c/6de2a650917bedaaefd65b17cede83c5e2c1dedd
- https://git.kernel.org/stable/c/cea34abc94b0a81e3a8b5cfb41cf45af37c2c67e
- https://git.kernel.org/stable/c/d129c3177d7b1138fd5066fcc63a698b3ba415b0
- https://git.kernel.org/stable/c/e8417353cbd078d10531ba3928e609c84ab09e6b