U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2026-64436

Change History

New CVE Received from kernel.org 7/25/2026 6:17:28 AM

Action Type Old Value New Value
Added Description

                  
                
              
In the Linux kernel, the following vulnerability has been resolved:

net: af_key: initialize alg_key_len for IPComp states

pfkey_msg2xfrm_state() handles the IPComp (SADB_X_SATYPE_IPCOMP) case by
allocating x->calg and copying only the algorithm name:

	x->calg = kmalloc_obj(*x->calg);
	if (!x->calg) {
		err = -ENOMEM;
		goto out;
	}
	strcpy(x->calg->alg_name, a->name);
	x->props.calgo = sa->sadb_sa_encrypt;

Unlike the authentication (x->aalg) and encryption (x->ealg) branches of
the same function, the compression branch never initializes
calg->alg_key_len.  IPComp carries no key and the allocation only
reserves sizeof(struct xfrm_algo) (i.e. no room for a key), so the field
is left containing uninitialized slab data.

calg->alg_key_len is later used as a length by xfrm_algo_clone() when an
IPComp state is cloned during XFRM_MSG_MIGRATE:

	xfrm_state_migrate()
	  xfrm_state_clone_and_setup()
	    x->calg = xfrm_algo_clone(orig->calg);
	      kmemdup(orig, xfrm_alg_len(orig));

where xfrm_alg_len() returns sizeof(*alg) + (alg_key_len + 7) / 8.  With
a non-zero garbage alg_key_len, kmemdup() reads past the end of the
68-byte calg object.  Adding an IPComp SA via PF_KEY and then migrating
it triggers (net-next, KASAN, init_on_alloc=0):

  BUG: KASAN: slab-out-of-bounds in kmemdup_noprof+0x44/0x60
  Read of size 4164 at addr ff11000025a74980 by task diag2/9287
  CPU: 3 UID: 0 PID: 9287 Comm: diag2 7.1.0-rc6-g903db046d557 #1
  Call Trace:
   <TASK>
   dump_stack_lvl+0x10e/0x1f0
   print_report+0xf7/0x600
   kasan_report+0xe4/0x120
   kasan_check_range+0x105/0x1b0
   __asan_memcpy+0x23/0x60
   kmemdup_noprof+0x44/0x60
   xfrm_state_migrate+0x70a/0x1da0
   xfrm_migrate+0x753/0x18a0
   xfrm_do_migrate+0xb47/0xf10
   xfrm_user_rcv_msg+0x411/0xb50
   netlink_rcv_skb+0x158/0x420
   xfrm_netlink_rcv+0x71/0x90
   netlink_unicast+0x584/0x850
   netlink_sendmsg+0x8b0/0xdc0
   ____sys_sendmsg+0x9f7/0xb90
   ___sys_sendmsg+0x134/0x1d0
   __sys_sendmsg+0x16d/0x220
   do_syscall_64+0x116/0x7d0
   entry_SYSCALL_64_after_hwframe+0x77/0x7f
   </TASK>

  Allocated by task 9287:
   kasan_save_stack+0x33/0x60
   kasan_save_track+0x14/0x30
   __kasan_kmalloc+0xaa/0xb0
   pfkey_add+0x2652/0x2ea0
   pfkey_process+0x6d0/0x830
   pfkey_sendmsg+0x42c/0x850
   __sys_sendto+0x461/0x4b0
   __x64_sys_sendto+0xe0/0x1c0
   do_syscall_64+0x116/0x7d0
   entry_SYSCALL_64_after_hwframe+0x77/0x7f

  The buggy address belongs to the object at ff11000025a74980
   which belongs to the cache kmalloc-96 of size 96
  The buggy address is located 0 bytes inside of
   allocated 68-byte region [ff11000025a74980, ff11000025a749c4)

Depending on the uninitialized value the same field can instead request
an oversized kmemdup() allocation and make the migration clone fail.

The XFRM netlink path is not affected: verify_one_alg() rejects an
XFRMA_ALG_COMP attribute shorter than xfrm_alg_len(), so a calg added via
XFRM_MSG_NEWSA is always self-consistent.

Initialize calg->alg_key_len to 0, matching the aalg/ealg branches.
Added Reference

                  
                
              
https://git.kernel.org/stable/c/01b9115b55018123ef2449ac4951f89147a8428e
Added Reference

                  
                
              
https://git.kernel.org/stable/c/273c06b81d2e902b21acc801ae18c8276c8a9b69
Added Reference

                  
                
              
https://git.kernel.org/stable/c/3f63d1752d90c0e28be931a48ab5d89bc97d637d
Added Reference

                  
                
              
https://git.kernel.org/stable/c/58e82fc3dedb57b1432292504415b224fd2d6acb
Added Reference

                  
                
              
https://git.kernel.org/stable/c/6de2a650917bedaaefd65b17cede83c5e2c1dedd
Added Reference

                  
                
              
https://git.kernel.org/stable/c/cea34abc94b0a81e3a8b5cfb41cf45af37c2c67e
Added Reference

                  
                
              
https://git.kernel.org/stable/c/d129c3177d7b1138fd5066fcc63a698b3ba415b0
Added Reference

                  
                
              
https://git.kernel.org/stable/c/e8417353cbd078d10531ba3928e609c84ab09e6b
Added Affected

                  
                
              
[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/key/af_key.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"80c9abaabf4283f7cf4a0b3597cd302506635b7f","lessThan":"58e82fc3dedb57b1432292504415b224fd2d6acb","versionType":"git","status":"affected"},{"version":"80c9abaabf4283f7cf4a0b3597cd302506635b7f","lessThan":"01b9115b55018123ef2449ac4951f89147a8428e","versionType":"git","status":"affected"},{"version":"80c9abaabf4283f7cf4a0b3597cd302506635b7f","lessThan":"3f63d1752d90c0e28be931a48ab5d89bc97d637d","versionType":"git","status":"affected"},{"version":"80c9abaabf4283f7cf4a0b3597cd302506635b7f","lessThan":"273c06b81d2e902b21acc801ae18c8276c8a9b69","versionType":"git","status":"affected"},{"version":"80c9abaabf4283f7cf4a0b3597cd302506635b7f","lessThan":"6de2a650917bedaaefd65b17cede83c5e2c1dedd","versionType":"git","status":"affected"},{"version":"80c9abaabf4283f7cf4a0b3597cd302506635b7f","lessThan":"e8417353cbd078d10531ba3928e609c84ab09e6b","versionType":"git","status":"affected"},{"version":"80c9abaabf4283f7cf4a0b3597cd302506635b7f","lessThan":"cea34abc94b0a81e3a8b5cfb41cf45af37c2c67e","versionType":"git","status":"affected"},{"version":"80c9abaabf4283f7cf4a0b3597cd302506635b7f","lessThan":"d129c3177d7b1138fd5066fcc63a698b3ba415b0","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/key/af_key.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.21","status":"affected"},{"version":"0","lessThan":"2.6.21","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]