Linux Kernel Vulnerability in Networking Device Reference Management
CVE-2026-64580

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
5 August 2026

What is CVE-2026-64580?

A vulnerability in the Linux kernel related to improper reference counting in networking code has been identified. This issue arises during error handling in the xfrm6_fill_dst() function, where a device reference is released improperly, leading to a potential use-after-free scenario. When an error occurs, the reference to the network device is decreased without nullifying the corresponding pointer. This mismanagement can trigger dereferencing of a previously freed object, resulting in undefined behavior. It is crucial for system administrators and developers to assess their kernel versions and apply necessary patches to mitigate this vulnerability.

Affected Version(s)

Linux 84c4a9dfbf430861e7588d95ae3ff61535dca351

Linux 84c4a9dfbf430861e7588d95ae3ff61535dca351 < 43de8a49335e611adb271bbd52e84dfbc11fc185

Linux 84c4a9dfbf430861e7588d95ae3ff61535dca351

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.