Linux Kernel Bridge Configuration Vulnerability by Vendor
CVE-2026-64537
What is CVE-2026-64537?
A flaw in the Linux kernel bridge allows for improper configuration of the CCM interval, potentially leading to resource exhaustion. Specifically, when an invalid expiration interval is set, the system may enter a tight loop, continuously allocating socket buffers until it runs out of memory (OOM). The issue arises from the lack of validation for the exp_interval at the time of configuration. To mitigate this, it is essential to constrain the interval to a valid range and reject starting CCM transmission when the interval has not been configured properly.
Affected Version(s)
Linux 2be665c3940d367e0a2a8128eb4985ce323f99a3 < 2870056a78961e0fecd652362ee9d3fcfd24a8a6
Linux 2be665c3940d367e0a2a8128eb4985ce323f99a3
Linux 2be665c3940d367e0a2a8128eb4985ce323f99a3 < 53788b134519e995699ea3721969c96a08d64575