๐Ÿ” CVE Alert

CVE-2026-64522

UNKNOWN 0.0

net/mlx5e: Fix eswitch mode block underflow on IPsec acquire SA

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Fix eswitch mode block underflow on IPsec acquire SA mlx5e_xfrm_add_state() handles acquire-flow temporary SAs by allocating software state and skipping hardware offload setup. That path jumps to the common success label before taking the eswitch mode block. After tunnel-mode validation was moved earlier, the common success label unconditionally calls mlx5_eswitch_unblock_mode(). For acquire SAs, this decrements esw->offloads.num_block_mode without a matching increment. Return directly after installing the acquire SA offload handle, so only the paths that successfully called mlx5_eswitch_block_mode() call the matching unblock.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Jul 25, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
22239eb258bc1e6ccdb2d3502fce1cc2b2a88386 < b5bd4249e430f5963d559708ee96a671716d2400 22239eb258bc1e6ccdb2d3502fce1cc2b2a88386 < ecafd8284e527666e83261e6e57a7c7341d591cb 22239eb258bc1e6ccdb2d3502fce1cc2b2a88386 < abe003b33223ff33552f291644bf35d9c2f992fb 993c4ba71596c30418ba5a0ddcf4f9c2f431466a 6.17.4 < 6.18
Linux / Linux
6.18

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/b5bd4249e430f5963d559708ee96a671716d2400 git.kernel.org: https://git.kernel.org/stable/c/ecafd8284e527666e83261e6e57a7c7341d591cb git.kernel.org: https://git.kernel.org/stable/c/abe003b33223ff33552f291644bf35d9c2f992fb