8.8
CVE-2026-64522
- EPSS 0.35%
- Veröffentlicht 25.07.2026 09:14:47
- Zuletzt bearbeitet 27.07.2026 05:16:56
- CVE-Watchlists
- Unerledigt
net/mlx5e: Fix eswitch mode block underflow on IPsec acquire SA
In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Fix eswitch mode block underflow on IPsec acquire SA mlx5e_xfrm_add_state() handles acquire-flow temporary SAs by allocating software state and skipping hardware offload setup. That path jumps to the common success label before taking the eswitch mode block. After tunnel-mode validation was moved earlier, the common success label unconditionally calls mlx5_eswitch_unblock_mode(). For acquire SAs, this decrements esw->offloads.num_block_mode without a matching increment. Return directly after installing the acquire SA offload handle, so only the paths that successfully called mlx5_eswitch_block_mode() call the matching unblock.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
22239eb258bc1e6ccdb2d3502fce1cc2b2a88386
Version <
b5bd4249e430f5963d559708ee96a671716d2400
Status
affected
Version
22239eb258bc1e6ccdb2d3502fce1cc2b2a88386
Version <
ecafd8284e527666e83261e6e57a7c7341d591cb
Status
affected
Version
22239eb258bc1e6ccdb2d3502fce1cc2b2a88386
Version <
abe003b33223ff33552f291644bf35d9c2f992fb
Status
affected
Version
993c4ba71596c30418ba5a0ddcf4f9c2f431466a
Status
affected
Version
6.17.4
Version <
6.18
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
6.18
Status
affected
Version
0
Version <
6.18
Status
unaffected
Version <=
6.18.*
Version
6.18.34
Status
unaffected
Version <=
7.0.*
Version
7.0.11
Status
unaffected
Version <=
*
Version
7.1
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.35% | 0.273 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
https://git.kernel.org/stable/c/b5bd4249e430f5963d559708ee96a671716d2400
https://git.kernel.org/stable/c/ecafd8284e527666e83261e6e57a7c7341d591cb
https://git.kernel.org/stable/c/abe003b33223ff33552f291644bf35d9c2f992fb