PT-2026-64855 · Linux+4 · Linux Kernel+4
CVE-2026-64531
·
Published
2026-07-06
·
Updated
2026-09-11
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
Open vSwitch stores generated flow actions as nlattrs, which use a
nla len field of type u16. A previous change allowed the total sw flow actions stream to exceed 64 KiB but removed the protection preventing a generated nested action attribute from exceeding U16 MAX. This allows an oversized generated container to be closed with a truncated nla len. Consequently, a subsequent dump or teardown process may traverse a structurally different stream than the one originally validated. Specifically, an oversized nested CLONE or CT action can lead to subsequent bytes in the generated stream being incorrectly interpreted as independent actions.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linuxmint
Linux Kernel
Openvswitch
Rocky Linux
Ubuntu