PT-2026-61231 · Linux+1 · Linux Kernel+1

CVE-2026-63914

·

Published

2026-07-19

·

Updated

2026-09-07

CVSS v3.1

7.3

High

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the Linux kernel where the xfrm send migrate() function in net/xfrm/xfrm user.c and the pfkey send migrate() function in net/key/af key.c hardcode the &init net for multicast notifications announcing successful XFRM MSG MIGRATE or SADB X MIGRATE. This causes notifications to be delivered to listeners on the init net network namespace instead of the issuing network namespace. Consequently, an IKE daemon in init net may receive notifications from other namespaces, while an IKE daemon in a non-init network namespace will not receive notifications of its own migration, breaking IKEv2 MOBIKE and address-update handling.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-63914
USN-8593-1
USN-8603-1
USN-8618-1
USN-8663-1
USN-8664-1
USN-8728-1

Affected Products

Linux Kernel
Ubuntu