In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: IPIP tunnel hardware offload is not yet support No driver… (CVE-2026-64410)
A vulnerability in the Linux kernel's netfilter flowtable component related to IPIP tunnel hardware offload has been resolved. The issue stems from the lack of driver support for IPIP tunnels, causing the hardware offload setup to be abandoned early. The patch introduces a stub to handle unsupported configurations and prevents repeated attempts to offload unsupported entries by checking the NF_FLOW_HW flag. This update improves handling of hardware offload work queuing for unsupported scenarios.
AI Analysis
Technical Summary
The Linux kernel netfilter flowtable component had a vulnerability where IPIP tunnel hardware offload was not supported by any driver, leading to improper handling of offload setup attempts. The fix adds a stub for future enhancements and modifies the flow offload logic to check the NF_FLOW_HW flag, ensuring that unsupported offload attempts are not retried on refresh. This prevents unnecessary work queuing and potential issues arising from unsupported hardware offload configurations.
Potential Impact
The vulnerability could cause inefficient processing or potential errors in the netfilter flowtable offload handling due to unsupported IPIP tunnel hardware offload attempts. There is no indication of direct exploitation or security compromise. No known exploits are reported in the wild.
Mitigation Recommendations
A patch has been applied to the Linux kernel to address this issue. Users should update to the fixed kernel version once available. Since no driver supports IPIP tunnel hardware offload yet, the patch prevents repeated unsupported offload attempts. No additional mitigation actions are indicated.
In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: IPIP tunnel hardware offload is not yet support No driver… (CVE-2026-64410)
Description
A vulnerability in the Linux kernel's netfilter flowtable component related to IPIP tunnel hardware offload has been resolved. The issue stems from the lack of driver support for IPIP tunnels, causing the hardware offload setup to be abandoned early. The patch introduces a stub to handle unsupported configurations and prevents repeated attempts to offload unsupported entries by checking the NF_FLOW_HW flag. This update improves handling of hardware offload work queuing for unsupported scenarios.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Linux kernel netfilter flowtable component had a vulnerability where IPIP tunnel hardware offload was not supported by any driver, leading to improper handling of offload setup attempts. The fix adds a stub for future enhancements and modifies the flow offload logic to check the NF_FLOW_HW flag, ensuring that unsupported offload attempts are not retried on refresh. This prevents unnecessary work queuing and potential issues arising from unsupported hardware offload configurations.
Potential Impact
The vulnerability could cause inefficient processing or potential errors in the netfilter flowtable offload handling due to unsupported IPIP tunnel hardware offload attempts. There is no indication of direct exploitation or security compromise. No known exploits are reported in the wild.
Mitigation Recommendations
A patch has been applied to the Linux kernel to address this issue. Users should update to the fixed kernel version once available. Since no driver supports IPIP tunnel hardware offload yet, the patch prevents repeated unsupported offload attempts. No additional mitigation actions are indicated.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-grq9-9wcr-7jrj
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-64410"]
- Ecosystems
- []
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a65420a9c2644c7f808414c
Added to database: 07/25/2026, 23:08:58 UTC
Last enriched: 07/25/2026, 23:26:24 UTC
Last updated: 07/26/2026, 05:02:37 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.