Improper input validation in Linux kernel - CVE-2026-64531
Published: July 28, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper handling of oversized nested action attributes in openvswitch flow action construction when processing user-supplied openvswitch nested action attributes. A local user can supply specially crafted nested CLONE or CT actions to cause a denial of service.
The issue occurs because a generated nested action attribute can be closed with a truncated nla_len, causing later dump or teardown operations to walk a structurally different action stream than the one that was validated.
Affected software
Debian Linux
linux (Debian package)
How to mitigate CVE-2026-64531
linux (Debian package) - update to 6.12.100-1
External References
- https://git.kernel.org/stable/c/1b41cbe05b184f8861712f0806cc0c4f5d8c6dfe
- https://git.kernel.org/stable/c/3f1f755366687d051174739fb99f7d560202f60b
- https://git.kernel.org/stable/c/ab855641241387db062a5e41d9ad6b8561542572
- https://git.kernel.org/stable/c/c66bd2626c2764f23764ff0f8277f44a9cfe8349
- https://git.kernel.org/stable/c/d573250d228401f707f4dbc09d11227a6215ee5f
- https://git.kernel.org/stable/c/dbd14f736be02cfe73049bd801af89becd1a0749
- https://git.kernel.org/stable/c/f1efff8858403191361a01269c6fe8dd7f55a385