Information disclosure in Linux kernel - CVE-2026-64553
Published: July 28, 2026
Vulnerability details
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to an information leak caused by improper clearing of padding bytes in PSAMPLE_ATTR_DATA handling in net/psample/psample.c when copying packet data into a netlink attribute. A local user can trigger processing of packet data whose length is not divisible by 4 bytes to disclose sensitive information.
The issue occurs because netlink attributes are padded to 4-byte boundaries.
Affected software
Debian Linux
linux (Debian package)
How to mitigate CVE-2026-64553
linux (Debian package) - update to 6.12.100-1
External References
- https://git.kernel.org/stable/c/0d3ea2ccddda442077fc44f11d873209c97ec50b
- https://git.kernel.org/stable/c/48930f6c59fd0056c2de46ce52bfe27d9c9e5eb6
- https://git.kernel.org/stable/c/794a0d8bdbb39e083ed42caccb86d687a9b53570
- https://git.kernel.org/stable/c/7fe7e6949964aa8ee6305f09db2dc9eede977bb3
- https://git.kernel.org/stable/c/a6cfb924ad74efce254e99c197d2e3863de70868
- https://git.kernel.org/stable/c/aedd02af1f8b0bceb7f42f5a21c41634ca9ed390
- https://git.kernel.org/stable/c/befe1ebe7fc2c65c80074bc34ceeb0a721ed3cd2
- https://git.kernel.org/stable/c/e2fa322782a2d7d8078f7bb20817e0aa9f7c32e9