CVE-2026-64576 | Linux Kernel up to 7.2-rc4 nexthop net/ipv4/nexthop.c nh_res_bucket_migrate extack uninitialized variable

SecurityVulns

A vulnerability, which was classified as very critical, has been found in Linux Kernel up to 6.6.147/6.12.100/6.18.41/7.1.5/7.2-rc4. Affected is the function nh_res_bucket_migrate of the file net/ipv4/nexthop.c of the component nexthop. Performing a manipulation of the argument extack results in use of uninitialized variable.

This vulnerability is identified as CVE-2026-64576. The attack can be initiated remotely. There is not any exploit available.

It is advisable to upgrade the affected component.VulDB Recent EntriesRead More