PT-2026-64743 · Linux · Linux

CVE-2026-64522

·

Publicado

2026-07-25

·

Atualizado

2026-07-25

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
net/mlx5e: Fix eswitch mode block underflow on IPsec acquire SA
mlx5e xfrm add state() handles acquire-flow temporary SAs by allocating software state and skipping hardware offload setup.
That path jumps to the common success label before taking the eswitch mode block. After tunnel-mode validation was moved earlier, the common success label unconditionally calls mlx5 eswitch unblock mode(). For acquire SAs, this decrements esw->offloads.num block mode without a matching increment.
Return directly after installing the acquire SA offload handle, so only the paths that successfully called mlx5 eswitch block mode() call the matching unblock.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2026-64522

Produtos afetados

Linux