OCTOBER 11, 2026
Live Feed
Back to database
Case File

CVE-2026-64553

UNKNOWN · CVSS N/A EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-07-27 · Last synced 2026-08-26

CyberRota Analysis

AI-Generated

The vulnerability in the Linux kernel affects the psample subsystem, where an information leak occurs due to improper handling of padding in netlink attributes. This can potentially expose sensitive data from memory, posing a risk to systems that rely on psample for packet sampling. Organizations using affected Linux distributions should prioritize patching to mitigate the risk of data exposure.

CVE
CVE-2026-64553
Severity
UNKNOWN
CVSS
N/A
EPSS
0.18%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: net: psample: fix info leak in PSAMPLE_ATTR_DATA psample open codes nla_put() presumably to avoid wiping the data with 0s just to override it with packet data. This open coding is missing clearing the pad, however, each netlink attr is padded to 4B and data_len may not be divisible by 4B.