{"id":"CVE-2026-64436","summary":"net: af_key: initialize alg_key_len for IPComp states","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: af_key: initialize alg_key_len for IPComp states\n\npfkey_msg2xfrm_state() handles the IPComp (SADB_X_SATYPE_IPCOMP) case by\nallocating x-\u003ecalg and copying only the algorithm name:\n\n\tx-\u003ecalg = kmalloc_obj(*x-\u003ecalg);\n\tif (!x-\u003ecalg) {\n\t\terr = -ENOMEM;\n\t\tgoto out;\n\t}\n\tstrcpy(x-\u003ecalg-\u003ealg_name, a-\u003ename);\n\tx-\u003eprops.calgo = sa-\u003esadb_sa_encrypt;\n\nUnlike the authentication (x-\u003eaalg) and encryption (x-\u003eealg) branches of\nthe same function, the compression branch never initializes\ncalg-\u003ealg_key_len.  IPComp carries no key and the allocation only\nreserves sizeof(struct xfrm_algo) (i.e. no room for a key), so the field\nis left containing uninitialized slab data.\n\ncalg-\u003ealg_key_len is later used as a length by xfrm_algo_clone() when an\nIPComp state is cloned during XFRM_MSG_MIGRATE:\n\n\txfrm_state_migrate()\n\t  xfrm_state_clone_and_setup()\n\t    x-\u003ecalg = xfrm_algo_clone(orig-\u003ecalg);\n\t      kmemdup(orig, xfrm_alg_len(orig));\n\nwhere xfrm_alg_len() returns sizeof(*alg) + (alg_key_len + 7) / 8.  With\na non-zero garbage alg_key_len, kmemdup() reads past the end of the\n68-byte calg object.  Adding an IPComp SA via PF_KEY and then migrating\nit triggers (net-next, KASAN, init_on_alloc=0):\n\n  BUG: KASAN: slab-out-of-bounds in kmemdup_noprof+0x44/0x60\n  Read of size 4164 at addr ff11000025a74980 by task diag2/9287\n  CPU: 3 UID: 0 PID: 9287 Comm: diag2 7.1.0-rc6-g903db046d557 #1\n  Call Trace:\n   \u003cTASK\u003e\n   dump_stack_lvl+0x10e/0x1f0\n   print_report+0xf7/0x600\n   kasan_report+0xe4/0x120\n   kasan_check_range+0x105/0x1b0\n   __asan_memcpy+0x23/0x60\n   kmemdup_noprof+0x44/0x60\n   xfrm_state_migrate+0x70a/0x1da0\n   xfrm_migrate+0x753/0x18a0\n   xfrm_do_migrate+0xb47/0xf10\n   xfrm_user_rcv_msg+0x411/0xb50\n   netlink_rcv_skb+0x158/0x420\n   xfrm_netlink_rcv+0x71/0x90\n   netlink_unicast+0x584/0x850\n   netlink_sendmsg+0x8b0/0xdc0\n   ____sys_sendmsg+0x9f7/0xb90\n   ___sys_sendmsg+0x134/0x1d0\n   __sys_sendmsg+0x16d/0x220\n   do_syscall_64+0x116/0x7d0\n   entry_SYSCALL_64_after_hwframe+0x77/0x7f\n   \u003c/TASK\u003e\n\n  Allocated by task 9287:\n   kasan_save_stack+0x33/0x60\n   kasan_save_track+0x14/0x30\n   __kasan_kmalloc+0xaa/0xb0\n   pfkey_add+0x2652/0x2ea0\n   pfkey_process+0x6d0/0x830\n   pfkey_sendmsg+0x42c/0x850\n   __sys_sendto+0x461/0x4b0\n   __x64_sys_sendto+0xe0/0x1c0\n   do_syscall_64+0x116/0x7d0\n   entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\n  The buggy address belongs to the object at ff11000025a74980\n   which belongs to the cache kmalloc-96 of size 96\n  The buggy address is located 0 bytes inside of\n   allocated 68-byte region [ff11000025a74980, ff11000025a749c4)\n\nDepending on the uninitialized value the same field can instead request\nan oversized kmemdup() allocation and make the migration clone fail.\n\nThe XFRM netlink path is not affected: verify_one_alg() rejects an\nXFRMA_ALG_COMP attribute shorter than xfrm_alg_len(), so a calg added via\nXFRM_MSG_NEWSA is always self-consistent.\n\nInitialize calg-\u003ealg_key_len to 0, matching the aalg/ealg branches.","modified":"2026-08-18T03:31:22.370053358Z","published":"2026-07-25T08:51:10.370Z","related":["openSUSE-SU-2026:11476-1"],"database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64436.json"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/01b9115b55018123ef2449ac4951f89147a8428e"},{"type":"WEB","url":"https://git.kernel.org/stable/c/273c06b81d2e902b21acc801ae18c8276c8a9b69"},{"type":"WEB","url":"https://git.kernel.org/stable/c/3f63d1752d90c0e28be931a48ab5d89bc97d637d"},{"type":"WEB","url":"https://git.kernel.org/stable/c/58e82fc3dedb57b1432292504415b224fd2d6acb"},{"type":"WEB","url":"https://git.kernel.org/stable/c/6de2a650917bedaaefd65b17cede83c5e2c1dedd"},{"type":"WEB","url":"https://git.kernel.org/stable/c/cea34abc94b0a81e3a8b5cfb41cf45af37c2c67e"},{"type":"WEB","url":"https://git.kernel.org/stable/c/d129c3177d7b1138fd5066fcc63a698b3ba415b0"},{"type":"WEB","url":"https://git.kernel.org/stable/c/e8417353cbd078d10531ba3928e609c84ab09e6b"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64436.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-64436"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"80c9abaabf4283f7cf4a0b3597cd302506635b7f"},{"fixed":"58e82fc3dedb57b1432292504415b224fd2d6acb"},{"fixed":"01b9115b55018123ef2449ac4951f89147a8428e"},{"fixed":"3f63d1752d90c0e28be931a48ab5d89bc97d637d"},{"fixed":"273c06b81d2e902b21acc801ae18c8276c8a9b69"},{"fixed":"6de2a650917bedaaefd65b17cede83c5e2c1dedd"},{"fixed":"e8417353cbd078d10531ba3928e609c84ab09e6b"},{"fixed":"cea34abc94b0a81e3a8b5cfb41cf45af37c2c67e"},{"fixed":"d129c3177d7b1138fd5066fcc63a698b3ba415b0"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64436.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.6.21"},{"fixed":"5.10.261"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.11.0"},{"fixed":"5.15.212"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.16.0"},{"fixed":"6.1.178"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.2.0"},{"fixed":"6.6.145"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.7.0"},{"fixed":"6.12.96"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.39"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.1.4"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64436.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"}]}