CVE-2026-64009
In the Linux kernel, the following vulnerability has been resolved:
xfrm: Check for underflow in xfrm_state_mtu
Leo Lin reported OOB write issue in esp component:
Check for underflow and return 1. This causes the sendmsg attempt to fail with ENETUNREACH.
Detalles técnicos trazas, registros y código del informe original
xfrm_state_mtu() returns u32 but performs its arithmetic in unsigned
modulo-2^32 space using an attacker-influenced "header_len + authsize +
net_adj" subtracted from a small "mtu" argument. A nobody user can
install an IPv4 ESP tunnel SA with a large authentication key
(XFRMA_ALG_AUTH_TRUNC, e.g. hmac(sha512), 64-byte key, 64-byte trunc),
configure a small interface MTU (68 bytes), and set XFRMA_TFCPAD to a
large value. When a single UDP datagram is then sent through the
tunnel, xfrm_state_mtu() underflows to a near-2^32 value, and
esp_output() consumes it as a signed int via:
padto = min(x->tfcpad, xfrm_state_mtu(x, mtu_cached))
esp.tfclen = padto - skb->len (assigned to int)
esp.tfclen ends up negative (e.g. -207). It is sign-extended to size_t
when passed to memset() inside esp_output_fill_trailer(), producing a
~16 EB write of zeroes at skb_tail_pointer(skb). KASAN logs it as
"Write of size 18446744073709551537 at addr ffff888...".CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 7.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.20%
- Percentil entre todas las CVEs puntuadas: 9
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1068Exploitation for Privilege Escalationprivilege escalation85 % - Impacto principal
T1499.004Application or System Exploitationimpact75 % - Impacto secundario
T1565.001Stored Data Manipulationimpact70 %
Vulnerabilidad local con AV:L/PR:L que permite a un usuario con privilegios bajos causar OOB write y DoS mediante configuración maliciosa de parámetros ESP (tfcpad, MTU, authsize); subdesbordamiento en xfrm_state_mtu genera escritura masiva de memoria.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/1021d2877b689a648b27815c854557a917122e93
- https://git.kernel.org/stable/c/2a41b1b31c61c52b972278ce1732a1443f5e89ed
- https://git.kernel.org/stable/c/3db50ceeacb52806d8fe86fb1dfe944df0b9f789
- https://git.kernel.org/stable/c/742b04d0550b0ec89dcbc99537ec88653bd1ad90
- https://git.kernel.org/stable/c/8014f70c4e6e5ab101ae3860a614e65e988372e3
- https://git.kernel.org/stable/c/820e501be8aee4b365d218d83227b314309c5fda
- https://git.kernel.org/stable/c/82ac903e0b519849647657b8c48d21237ada06a2
- https://git.kernel.org/stable/c/fccd685b32df5aaf6bad4381eeda216468e283f0
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-64009",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Secondary",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.8,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "c5c2523893747f88a83376abad310c8ad13f7197",
"lessThan": "8014f70c4e6e5ab101ae3860a614e65e988372e3",
"versionType": "git"
},
{
"status": "affected",
"version": "c5c2523893747f88a83376abad310c8ad13f7197",
"lessThan": "1021d2877b689a648b27815c854557a917122e93",
"versionType": "git"
},
{
"status": "affected",
"version": "c5c2523893747f88a83376abad310c8ad13f7197",
"lessThan": "2a41b1b31c61c52b972278ce1732a1443f5e89ed",
"versionType": "git"
},
{
"status": "affected",
"version": "c5c2523893747f88a83376abad310c8ad13f7197",
"lessThan": "fccd685b32df5aaf6bad4381eeda216468e283f0",
"versionType": "git"
},
{
"status": "affected",
"version": "c5c2523893747f88a83376abad310c8ad13f7197",
"lessThan": "820e501be8aee4b365d218d83227b314309c5fda",
"versionType": "git"
},
{
"status": "affected",
"version": "c5c2523893747f88a83376abad310c8ad13f7197",
"lessThan": "82ac903e0b519849647657b8c48d21237ada06a2",
"versionType": "git"
},
{
"status": "affected",
"version": "c5c2523893747f88a83376abad310c8ad13f7197",
"lessThan": "3db50ceeacb52806d8fe86fb1dfe944df0b9f789",
"versionType": "git"
},
{
"status": "affected",
"version": "c5c2523893747f88a83376abad310c8ad13f7197",
"lessThan": "742b04d0550b0ec89dcbc99537ec88653bd1ad90",
"versionType": "git"
}
],
"programFiles": [
"net/xfrm/xfrm_state.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.22"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "2.6.22",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.10.259",
"versionType": "semver",
"lessThanOrEqual": "5.10.*"
},
{
"status": "unaffected",
"version": "5.15.210",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.176",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.143",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.93",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.35",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.0.12",
"versionType": "semver",
"lessThanOrEqual": "7.0.*"
},
{
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"net/xfrm/xfrm_state.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-07-19T16:17:40.663",
"references": [
{
"url": "https://git.kernel.org/stable/c/1021d2877b689a648b27815c854557a917122e93",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/2a41b1b31c61c52b972278ce1732a1443f5e89ed",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/3db50ceeacb52806d8fe86fb1dfe944df0b9f789",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/742b04d0550b0ec89dcbc99537ec88653bd1ad90",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/8014f70c4e6e5ab101ae3860a614e65e988372e3",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/820e501be8aee4b365d218d83227b314309c5fda",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/82ac903e0b519849647657b8c48d21237ada06a2",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/fccd685b32df5aaf6bad4381eeda216468e283f0",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Awaiting Analysis",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: Check for underflow in xfrm_state_mtu\n\nLeo Lin reported OOB write issue in esp component:\n\n xfrm_state_mtu() returns u32 but performs its arithmetic in unsigned\n modulo-2^32 space using an attacker-influenced \"header_len + authsize +\n net_adj\" subtracted from a small \"mtu\" argument. A nobody user can\n install an IPv4 ESP tunnel SA with a large authentication key\n (XFRMA_ALG_AUTH_TRUNC, e.g. hmac(sha512), 64-byte key, 64-byte trunc),\n configure a small interface MTU (68 bytes), and set XFRMA_TFCPAD to a\n large value. When a single UDP datagram is then sent through the\n tunnel, xfrm_state_mtu() underflows to a near-2^32 value, and\n esp_output() consumes it as a signed int via:\n\n padto = min(x->tfcpad, xfrm_state_mtu(x, mtu_cached))\n esp.tfclen = padto - skb->len (assigned to int)\n\n esp.tfclen ends up negative (e.g. -207). It is sign-extended to size_t\n when passed to memset() inside esp_output_fill_trailer(), producing a\n ~16 EB write of zeroes at skb_tail_pointer(skb). KASAN logs it as\n \"Write of size 18446744073709551537 at addr ffff888...\".\n\nCheck for underflow and return 1. This causes the sendmsg attempt to\nfail with ENETUNREACH."
}
],
"lastModified": "2026-07-30T14:59:47.950",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}