Improper Check for Unusual or Exceptional Conditions in Linux kernel - CVE-2026-64410

 

Improper Check for Unusual or Exceptional Conditions in Linux kernel - CVE-2026-64410

Published: July 28, 2026


Vulnerability identifier: #VU139869
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-64410
CWE-ID: CWE-754
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper handling of unsupported hardware offload configurations in netfilter flowtable hardware offload when processing IPIP tunnel flows. A remote attacker can send specially crafted network traffic to cause a denial of service.

The issue occurs in the IPIP tunnel hardware offload path, where unsupported flows may still be enqueued for offload processing.


Affected software

Linux kernel

How to mitigate CVE-2026-64410

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3

External References

Related Security Bulletins