PT-2026-64855 · Linux+4 · Linux Kernel+4

CVE-2026-64531

·

Published

2026-07-06

·

Updated

2026-09-11

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description Open vSwitch stores generated flow actions as nlattrs, which use a nla len field of type u16. A previous change allowed the total sw flow actions stream to exceed 64 KiB but removed the protection preventing a generated nested action attribute from exceeding U16 MAX. This allows an oversized generated container to be closed with a truncated nla len. Consequently, a subsequent dump or teardown process may traverse a structurally different stream than the one originally validated. Specifically, an oversized nested CLONE or CT action can lead to subsequent bytes in the generated stream being incorrectly interpreted as independent actions.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:53329
ALSA-2026:53330
AZL-93965
BDU:2026-13774
CVE-2026-64531
OPENSUSE-SU-2026:11476-1
USN-8643-1
USN-8643-2
USN-8643-3
USN-8643-4
USN-8643-5
USN-8656-1
USN-8658-1
USN-8658-2
USN-8658-3
USN-8658-4
USN-8659-1
USN-8659-2
USN-8659-3
USN-8659-4
USN-8660-1
USN-8661-1
USN-8661-2
USN-8661-3
USN-8661-4
USN-8728-1
USN-8748-1

Affected Products

Linuxmint
Linux Kernel
Openvswitch
Rocky Linux
Ubuntu