Improper input validation in Linux kernel - CVE-2026-64531
Published: July 28, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper handling of oversized nested action attributes in openvswitch flow action construction when processing user-supplied openvswitch nested action attributes. A local user can supply specially crafted nested CLONE or CT actions to cause a denial of service.
The issue occurs because a generated nested action attribute can be closed with a truncated nla_len, causing later dump or teardown operations to walk a structurally different action stream than the one that was validated.
Affected software
Debian Linux
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux Server - AUS
Ubuntu
openEuler
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
kpatch-patch-5_14_0-284_172_1 (Red Hat package)
kpatch-patch-5_14_0-687_10_1 (Red Hat package)
kpatch-patch-6_12_0-211_16_1 (Red Hat package)
kpatch-patch-5_14_0-427_126_1 (Red Hat package)
kpatch-patch-5_14_0-284_158_1 (Red Hat package)
kpatch-patch-5_14_0-427_113_1 (Red Hat package)
kpatch-patch-5_14_0-284_148_1 (Red Hat package)
kpatch-patch-5_14_0-427_100_1 (Red Hat package)
kpatch-patch-5_14_0-284_134_1 (Red Hat package)
kpatch-patch-5_14_0-427_84_1 (Red Hat package)
kpatch-patch-5_14_0-284_117_1 (Red Hat package)
kpatch-patch-5_14_0-427_68_2 (Red Hat package)
kernel (Red Hat package)
kernel-rt (Red Hat package)
linux-fips (Ubuntu package)
linux-lowlatency (Ubuntu package)
linux (Ubuntu package)
linux-azure-5.15 (Ubuntu package)
linux-azure (Ubuntu package)
linux-ibm (Ubuntu package)
linux-aws-5.15 (Ubuntu package)
linux-azure-fde-5.15 (Ubuntu package)
kernel
bpftool
bpftool-debuginfo
kernel-debugsource
kernel-source
python3-perf
perf-debuginfo
perf
python3-perf-debuginfo
kernel-tools-devel
kernel-tools-debuginfo
kernel-tools
kernel-headers
kernel-extra-modules
kernel-devel
kernel-debuginfo
linux-gke (Ubuntu package)
linux-hwe-6.8 (Ubuntu package)
linux-aws-6.8 (Ubuntu package)
linux-azure-6.8 (Ubuntu package)
linux-nvidia (Ubuntu package)
linux (Debian package)
linux-hwe-7.0 (Ubuntu package)
linux-gcp (Ubuntu package)
linux-oracle (Ubuntu package)
linux-gcp-7.0 (Ubuntu package)
Red Hat OpenShift Container Platform
How to mitigate CVE-2026-64531
kpatch-patch-5_14_0-284_172_1 (Red Hat package) - update to 1-7.el9_2
kpatch-patch-5_14_0-687_10_1 (Red Hat package) - update to 1-7.el9_8
kpatch-patch-6_12_0-211_16_1 (Red Hat package) - update to 1-7.el10_2
kpatch-patch-5_14_0-427_126_1 (Red Hat package) - update to 1-8.el9_4
kpatch-patch-5_14_0-284_158_1 (Red Hat package) - update to 1-10.el9_2
kpatch-patch-5_14_0-427_113_1 (Red Hat package) - update to 1-11.el9_4
kpatch-patch-5_14_0-284_148_1 (Red Hat package) - update to 1-12.el9_2
kpatch-patch-5_14_0-427_100_1 (Red Hat package) - update to 1-13.el9_4
kpatch-patch-5_14_0-284_134_1 (Red Hat package) - update to 1-14.el9_2
kpatch-patch-5_14_0-427_84_1 (Red Hat package) - update to 1-15.el9_4
kpatch-patch-5_14_0-284_117_1 (Red Hat package) - update to 1-20.el9_2
kpatch-patch-5_14_0-427_68_2 (Red Hat package) - update to 1-20.el9_4
Red Hat OpenShift Container Platform - update to 4.22.11
kernel (Red Hat package) - addressed in versions 5.14.0-284.186.1.el9_2, 5.14.0-427.143.1.el9_4, 5.14.0-687.38.1.el9_8, 6.12.0-211.46.1.el10_2
kernel-rt (Red Hat package) - update to 5.14.0-284.186.1.rt14.471.el9_2
linux-fips (Ubuntu package) - addressed in versions 5.15.0.190.111, 5.15.0-190.200+fips1, 5.15.0.1110.109, 5.15.0-1110.116
linux-lowlatency (Ubuntu package) - addressed in versions 5.15.0.190.157, 5.15.0-190.200
linux (Ubuntu package) - addressed in versions 5.15.0.190.169, 5.15.0-190.200, 5.15.0.1066.66, 5.15.0-1066.68, 5.15.0-1066.68~20.04.1, 5.15.0-1077.80, 5.15.0-1077.81, 5.15.0.1097.96, 5.15.0-1097.105, 5.15.0.1106.102, 5.15.0-1106.108, 5.15.0.1106.110, 5.15.0-1106.111, 5.15.0-1108.112~20.04.1, 5.15.0.1109.108, 5.15.0.1109.109, 5.15.0-1109.110, 5.15.0-1109.115, 5.15.0-1109.115~20.04.1, 5.15.0.1111.107, 5.15.0-1111.117, 5.15.0-1111.117~20.04.1, 5.15.0.1113.117, 5.15.0-1113.122, 5.15.0.1114.110, 5.15.0.1114.117, 5.15.0-1114.121, 5.15.0-1114.121+fips1, 5.15.0.1119.104, 5.15.0-1119.128+fips1, 6.8.0-138.138+fips1, 6.8.0-1035.36, 6.8.0-1048.52, 6.8.0-1060.63.1, 6.8.0-1063.66, 6.8.0-1063.66+fips1, 6.8.0-1065.73~22.04.1, 6.8.0-1066.74, 6.8.0-1066.74+fips1, 6.8.0-1066.74~22.04.1, 6.8.1-1058.59, 6.8.1-1058.59~22.04.1, 7.0.0-30.30, 7.0.0-30.30.1, 7.0.0-1011.11, 7.0.0-1011.11~24.04.1, 7.0.0-1012.12, 7.0.0-1017.17
linux-azure-5.15 (Ubuntu package) - addressed in versions 5.15.0-190.200~20.04.1, 5.15.0.1114.104, 5.15.0.1114.111, 5.15.0-1114.124, 5.15.0-1114.124+fips1, 5.15.0-1119.128~20.04.1
linux-azure (Ubuntu package) - addressed in versions 5.15.0-1055.55, 5.15.0.1055.57, 5.15.0.1119.117, 5.15.0-1119.128, 7.0.0-1011.11, 7.0.0-1012.12
linux-ibm (Ubuntu package) - addressed in versions 5.15.0.1108.105, 5.15.0-1108.112
linux-aws-5.15 (Ubuntu package) - addressed in versions 5.15.0-1114.121~20.04.1, 5.15.0-1114.124~20.04.1
linux-azure-fde-5.15 (Ubuntu package) - update to 5.15.0-1119.128~20.04.1
kernel - update to 6.6.0-145.3.29.160
bpftool - update to 6.6.0-145.3.29.160
bpftool-debuginfo - update to 6.6.0-145.3.29.160
kernel-debugsource - update to 6.6.0-145.3.29.160
kernel-source - update to 6.6.0-145.3.29.160
python3-perf - update to 6.6.0-145.3.29.160
perf-debuginfo - update to 6.6.0-145.3.29.160
perf - update to 6.6.0-145.3.29.160
python3-perf-debuginfo - update to 6.6.0-145.3.29.160
kernel-tools-devel - update to 6.6.0-145.3.29.160
kernel-tools-debuginfo - update to 6.6.0-145.3.29.160
kernel-tools - update to 6.6.0-145.3.29.160
kernel-headers - update to 6.6.0-145.3.29.160
kernel-extra-modules - update to 6.6.0-145.3.29.160
kernel-devel - update to 6.6.0-145.3.29.160
kernel-debuginfo - update to 6.6.0-145.3.29.160
linux-gke (Ubuntu package) - addressed in versions 6.8.0-138.138.1, 6.8.0-138.138.1~22.04.1, 6.8.0-1061.69
linux-hwe-6.8 (Ubuntu package) - update to 6.8.0-138.138~22.04.1
linux-aws-6.8 (Ubuntu package) - addressed in versions 6.8.0-1032.34~22.04.1, 6.8.0-1063.66~22.04.1, 6.8.0-1064.71, 6.8.0-1064.71~22.04.1, 6.8.0-1065.73+fips1
linux-azure-6.8 (Ubuntu package) - addressed in versions 6.8.0-1060.63~22.04.1, 6.8.0-1063.64, 6.8.0-1063.64~22.04.1, 6.8.0-1063.67, 6.8.0-1065.73~22.04.1, 6.8.0-2052.54
linux-nvidia (Ubuntu package) - addressed in versions 6.8.0-1061.64, 6.8.0-1061.64.1, 6.8.0-1061.64~22.04.1
linux (Debian package) - update to 6.12.100-1
linux-hwe-7.0 (Ubuntu package) - update to 7.0.0-30.30~24.04.1
linux-gcp (Ubuntu package) - addressed in versions 7.0.0-1005.6, 7.0.0-1010.10
linux-oracle (Ubuntu package) - update to 7.0.0-1010.10
linux-gcp-7.0 (Ubuntu package) - update to 7.0.0-1011.11~24.04.1
External References
- https://git.kernel.org/stable/c/1b41cbe05b184f8861712f0806cc0c4f5d8c6dfe
- https://git.kernel.org/stable/c/3f1f755366687d051174739fb99f7d560202f60b
- https://git.kernel.org/stable/c/ab855641241387db062a5e41d9ad6b8561542572
- https://git.kernel.org/stable/c/c66bd2626c2764f23764ff0f8277f44a9cfe8349
- https://git.kernel.org/stable/c/d573250d228401f707f4dbc09d11227a6215ee5f
- https://git.kernel.org/stable/c/dbd14f736be02cfe73049bd801af89becd1a0749
- https://git.kernel.org/stable/c/f1efff8858403191361a01269c6fe8dd7f55a385
Related Security Bulletins
- Improper input validation in Linux kernel openvswitch
- Debian update for linux
- Red Hat Enterprise Linux 9 update for kernel
- Red Hat Enterprise Linux 9 update for kernel-rt
- Red Hat Enterprise Linux 9 update for kernel
- Red Hat Enterprise Linux 9 update for kernel
- Red Hat Enterprise Linux 10 update for kernel
- Ubuntu update for linux
- Ubuntu update for linux-gke
- Ubuntu update for linux-hwe-6.8
- Ubuntu update for linux-azure-5.15
- Ubuntu update for linux-gcp
- Ubuntu update for linux
- Ubuntu update for linux
- Ubuntu update for linux-nvidia
- Ubuntu update for linux-hwe-7.0
- Ubuntu update for linux-ibm
- Ubuntu update for linux-lowlatency
- Red Hat Enterprise Linux 10 update for kpatch-patch-6_12_0-211_16_1
- Red Hat Enterprise Linux 9 update for multiple packages
- Red Hat Enterprise Linux 9 update for multiple packages
- Red Hat Enterprise Linux 9 update for kpatch-patch-5_14_0-687_10_1
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.22
- Ubuntu update for linux-azure
- Ubuntu update for linux-aws-6.8
- Ubuntu update for linux-azure
- Ubuntu update for linux-oracle
- Ubuntu update for linux-fips
- Ubuntu update for linux-azure-fde-5.15
- Ubuntu update for linux-azure-6.8
- Ubuntu update for linux-aws-5.15
- openEuler 24.03 LTS SP3 update for kernel
- Ubuntu update for linux-gcp-7.0