PT-2026-64743 · Linux · Linux

CVE-2026-64522

·

Published

2026-07-25

·

Updated

2026-07-25

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
net/mlx5e: Fix eswitch mode block underflow on IPsec acquire SA
mlx5e xfrm add state() handles acquire-flow temporary SAs by allocating software state and skipping hardware offload setup.
That path jumps to the common success label before taking the eswitch mode block. After tunnel-mode validation was moved earlier, the common success label unconditionally calls mlx5 eswitch unblock mode(). For acquire SAs, this decrements esw->offloads.num block mode without a matching increment.
Return directly after installing the acquire SA offload handle, so only the paths that successfully called mlx5 eswitch block mode() call the matching unblock.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-64522

Affected Products

Linux