Linux Kernel Vulnerability in Nexthop Component by Linux Foundation
CVE-2026-64576

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
5 August 2026

What is CVE-2026-64576?

A vulnerability exists in the nexthop component of the Linux kernel, where an uninitialized netlink_ext_ack is passed to critical functions. This can lead to dereferencing stale pointers and result in a kernel panic. The fault occurs when initialization fails and improperly propagated errors occur, resulting in potential system crashes due to undefined behavior. Patching the affected code to ensure proper initialization of error handling structures is essential to mitigate this risk.

Affected Version(s)

Linux 7c37c7e00411b3d1e0c5292368317aca69d1f324

Linux 7c37c7e00411b3d1e0c5292368317aca69d1f324 < 3081702ea5aca0aeed9c1ade8eadf6cde8db6b7d

Linux 7c37c7e00411b3d1e0c5292368317aca69d1f324

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.