Linux Kernel Vulnerability Affects xfrm State Management
CVE-2026-68415

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
10 August 2026

What is CVE-2026-68415?

A vulnerability in the Linux kernel's xfrm module affects state management, potentially causing kernel panics and system crashes. Specifically, a failure in the IP transport family state setup could lead to stale callbacks remaining in memory even after a failed initialization. This flaw allows for a scenario where garbage collection does not clear these callbacks, leading to fatal exceptions when the kernel attempts to dereference these stale pointers. The impact of this vulnerability may manifest as abrupt system instability or crashes due to kernel panics, posing significant risks to system security and reliability.

Affected Version(s)

Linux 4b3faf610cc63bfac972711635eafbca5e7d7117 < 9845a35986a658816f7752f7ebd7c455a4c7dfdf

Linux 4b3faf610cc63bfac972711635eafbca5e7d7117

Linux 4b3faf610cc63bfac972711635eafbca5e7d7117 < 2538bd3cd1ff5af655908469544ac7b7ae259386

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.