In the Linux kernel, the following vulnerability has been resolved: netfilter: handle unreadable frags sashiko reports: When an skb with unreadable… (CVE-2026-64414)
A vulnerability in the Linux kernel's netfilter subsystem related to handling unreadable skb fragments has been resolved. The issue involved unsafe processing of skb fragments when skb_frags_readable(skb) returns false, potentially causing improper behavior in modules like u32, nfnetlink_queue, and nfnetlink_log. The fix ensures safe error handling and restricts operations to the linear part of skb data where appropriate.
AI Analysis
Technical Summary
CVE-2026-64414 addresses a vulnerability in the Linux kernel netfilter subsystem where skb (socket buffer) fragments that are unreadable could lead to unsafe processing. Specifically, when skb_frags_readable(skb) returns false, the u32 module's skb_copy_bits() function now safely returns a negative error code. Additional mitigations include the xt_u32 module bailing out with hotdrop, gather_frags returning -1 as if no fragment header was present, and nfnetlink_queue and nfnetlink_log restricting operations to the linear part of skb data. The patch also corrected skb_zerocopy helpers to avoid copying the readable flag incorrectly, preventing broken behavior in nfnetlink_queue.
Potential Impact
The vulnerability could cause improper handling of unreadable skb fragments in netfilter modules, potentially leading to incorrect packet processing or kernel errors. No known exploits in the wild have been reported. The impact is limited to kernel packet filtering and logging subsystems that handle fragmented skb data.
Mitigation Recommendations
A fix has been implemented in the Linux kernel to safely handle unreadable skb fragments in netfilter components. Users should apply the official kernel updates that include this patch. Since this is a kernel-level vulnerability, upgrading to a patched kernel version is the recommended remediation. Patch status is not explicitly confirmed in the provided data; users should consult the Linux kernel vendor advisory for the exact fixed versions and update accordingly.
In the Linux kernel, the following vulnerability has been resolved: netfilter: handle unreadable frags sashiko reports: When an skb with unreadable… (CVE-2026-64414)
Description
A vulnerability in the Linux kernel's netfilter subsystem related to handling unreadable skb fragments has been resolved. The issue involved unsafe processing of skb fragments when skb_frags_readable(skb) returns false, potentially causing improper behavior in modules like u32, nfnetlink_queue, and nfnetlink_log. The fix ensures safe error handling and restricts operations to the linear part of skb data where appropriate.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-64414 addresses a vulnerability in the Linux kernel netfilter subsystem where skb (socket buffer) fragments that are unreadable could lead to unsafe processing. Specifically, when skb_frags_readable(skb) returns false, the u32 module's skb_copy_bits() function now safely returns a negative error code. Additional mitigations include the xt_u32 module bailing out with hotdrop, gather_frags returning -1 as if no fragment header was present, and nfnetlink_queue and nfnetlink_log restricting operations to the linear part of skb data. The patch also corrected skb_zerocopy helpers to avoid copying the readable flag incorrectly, preventing broken behavior in nfnetlink_queue.
Potential Impact
The vulnerability could cause improper handling of unreadable skb fragments in netfilter modules, potentially leading to incorrect packet processing or kernel errors. No known exploits in the wild have been reported. The impact is limited to kernel packet filtering and logging subsystems that handle fragmented skb data.
Mitigation Recommendations
A fix has been implemented in the Linux kernel to safely handle unreadable skb fragments in netfilter components. Users should apply the official kernel updates that include this patch. Since this is a kernel-level vulnerability, upgrading to a patched kernel version is the recommended remediation. Patch status is not explicitly confirmed in the provided data; users should consult the Linux kernel vendor advisory for the exact fixed versions and update accordingly.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-p7m6-q3fj-3f6g
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-64414"]
- Ecosystems
- []
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a65420a9c2644c7f8083bc9
Added to database: 07/25/2026, 23:08:58 UTC
Last enriched: 07/25/2026, 23:25:58 UTC
Last updated: 07/26/2026, 04:44:34 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.