Buffer Overflow Vulnerability in Linux Kernel Affecting ESP Component
CVE-2026-64009
What is CVE-2026-64009?
A vulnerability exists in the Linux kernel's xfrm_state_mtu function within the ESP component that can lead to a buffer overflow due to an unchecked underflow. An attacker can exploit this weakness by manipulating the MTU and authentication key settings, potentially resulting in a write operation that exceeds the boundary of allocated memory. This could allow for a significant overflow write, which might compromise system stability and security. To mitigate this vulnerability, it is critical to check for underflows and ensure proper error handling in the affected function.
Affected Version(s)
Linux c5c2523893747f88a83376abad310c8ad13f7197 < 8014f70c4e6e5ab101ae3860a614e65e988372e3
Linux c5c2523893747f88a83376abad310c8ad13f7197 < 1021d2877b689a648b27815c854557a917122e93
Linux c5c2523893747f88a83376abad310c8ad13f7197 < 2a41b1b31c61c52b972278ce1732a1443f5e89ed