Out-of-bounds write in Linux kernel - CVE-2026-64566
Published: August 6, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to memory corruption in iptfs_skb_add_frags() when processing shared fragment references for nested transport-mode SA traffic. A local user can trigger crafted packet processing to cause a denial of service.
The issue can lead to kernel-visible memory corruption and a kernel panic when ESP decrypts in place on fragments still referenced by the outer IPTFS SKB.