IPsec Acquired Session Authentication Vulnerability in Linux Kernel
CVE-2026-64522

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
25 July 2026

What is CVE-2026-64522?

A vulnerability in the Linux kernel's handling of IPsec acquired session authentication can lead to improper state management during the allocation of software states. Specifically, when mlx5e_xfrm_add_state() deals with acquire-flow temporary Security Associations (SAs), it fails to properly manage the eswitch mode block, resulting in a decrement of the block mode count without matching increments. This manipulation in the flow can create potential security risks in handling IPsec connections, necessitating a thorough review of affected systems.

Affected Version(s)

Linux 22239eb258bc1e6ccdb2d3502fce1cc2b2a88386

Linux 22239eb258bc1e6ccdb2d3502fce1cc2b2a88386

Linux 22239eb258bc1e6ccdb2d3502fce1cc2b2a88386

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.