{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.1.180-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.12.96-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "7.1.4-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux-6.12"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.12.100-1~deb12u1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  net: af_key: initialize alg_key_len for IPComp states  pfkey_msg2xfrm_state() handles the IPComp (SADB_X_SATYPE_IPCOMP) case by allocating x-\u003ecalg and copying only the algorithm name:  \tx-\u003ecalg = kmalloc_obj(*x-\u003ecalg); \tif (!x-\u003ecalg) { \t\terr = -ENOMEM; \t\tgoto out; \t} \tstrcpy(x-\u003ecalg-\u003ealg_name, a-\u003ename); \tx-\u003eprops.calgo = sa-\u003esadb_sa_encrypt;  Unlike the authentication (x-\u003eaalg) and encryption (x-\u003eealg) branches of the same function, the compression branch never initializes calg-\u003ealg_key_len.  IPComp carries no key and the allocation only reserves sizeof(struct xfrm_algo) (i.e. no room for a key), so the field is left containing uninitialized slab data.  calg-\u003ealg_key_len is later used as a length by xfrm_algo_clone() when an IPComp state is cloned during XFRM_MSG_MIGRATE:  \txfrm_state_migrate() \t  xfrm_state_clone_and_setup() \t    x-\u003ecalg = xfrm_algo_clone(orig-\u003ecalg); \t      kmemdup(orig, xfrm_alg_len(orig));  where xfrm_alg_len() returns sizeof(*alg) + (alg_key_len + 7) / 8.  With a non-zero garbage alg_key_len, kmemdup() reads past the end of the 68-byte calg object.  Adding an IPComp SA via PF_KEY and then migrating it triggers (net-next, KASAN, init_on_alloc=0):    BUG: KASAN: slab-out-of-bounds in kmemdup_noprof+0x44/0x60   Read of size 4164 at addr ff11000025a74980 by task diag2/9287   CPU: 3 UID: 0 PID: 9287 Comm: diag2 7.1.0-rc6-g903db046d557 #1   Call Trace:    \u003cTASK\u003e    dump_stack_lvl+0x10e/0x1f0    print_report+0xf7/0x600    kasan_report+0xe4/0x120    kasan_check_range+0x105/0x1b0    __asan_memcpy+0x23/0x60    kmemdup_noprof+0x44/0x60    xfrm_state_migrate+0x70a/0x1da0    xfrm_migrate+0x753/0x18a0    xfrm_do_migrate+0xb47/0xf10    xfrm_user_rcv_msg+0x411/0xb50    netlink_rcv_skb+0x158/0x420    xfrm_netlink_rcv+0x71/0x90    netlink_unicast+0x584/0x850    netlink_sendmsg+0x8b0/0xdc0    ____sys_sendmsg+0x9f7/0xb90    ___sys_sendmsg+0x134/0x1d0    __sys_sendmsg+0x16d/0x220    do_syscall_64+0x116/0x7d0    entry_SYSCALL_64_after_hwframe+0x77/0x7f    \u003c/TASK\u003e    Allocated by task 9287:    kasan_save_stack+0x33/0x60    kasan_save_track+0x14/0x30    __kasan_kmalloc+0xaa/0xb0    pfkey_add+0x2652/0x2ea0    pfkey_process+0x6d0/0x830    pfkey_sendmsg+0x42c/0x850    __sys_sendto+0x461/0x4b0    __x64_sys_sendto+0xe0/0x1c0    do_syscall_64+0x116/0x7d0    entry_SYSCALL_64_after_hwframe+0x77/0x7f    The buggy address belongs to the object at ff11000025a74980    which belongs to the cache kmalloc-96 of size 96   The buggy address is located 0 bytes inside of    allocated 68-byte region [ff11000025a74980, ff11000025a749c4)  Depending on the uninitialized value the same field can instead request an oversized kmemdup() allocation and make the migration clone fail.  The XFRM netlink path is not affected: verify_one_alg() rejects an XFRMA_ALG_COMP attribute shorter than xfrm_alg_len(), so a calg added via XFRM_MSG_NEWSA is always self-consistent.  Initialize calg-\u003ealg_key_len to 0, matching the aalg/ealg branches.",
  "id": "DEBIAN-CVE-2026-64436",
  "modified": "2026-09-14T16:47:27.638321111Z",
  "published": "2026-07-25T10:17:28.010Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-64436"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H",
      "type": "CVSS_V3"
    }
  ],
  "upstream": [
    "CVE-2026-64436"
  ]
}