CVE-2026-64531: net: openvswitch: reject oversized nested action attrs
In the Linux kernel, the following vulnerability has been resolved:
Other sources
net: openvswitch: reject oversized nested action attrs
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.6.145.2-1 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.1.187-1Fixed in 6.12.107-1Fixed in 7.1.13-1 - Upgrade
Upgrade
debian/linux-6.12to a version that resolves this vulnerability.Fixed in 6.12.101-1~deb12u1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch a1e64addf3ff - Configuration
Apply the fix for Open vSwitch to reject generated nested action containers whose nested nlattr nla_len would exceed U16_MAX, while keeping the existing allowance for total sw_flow_actions stream growth beyond 64 KiB; ensure the close/rejection error is propagated through all callers.
Linux kernel (net: openvswitch) reject oversized nested action attrs (nla_len/u16) = enabled
Event History
Frequently Asked Questions
What is the severity of CVE-2026-64531?
CVE-2026-64531 has been assigned a risk score of 57.
How do I fix CVE-2026-64531?
To fix CVE-2026-64531, update your Linux kernel to the latest stable version that includes the security patch.
What components are affected by CVE-2026-64531?
CVE-2026-64531 affects the Open vSwitch component within the Linux kernel.
What type of vulnerability is CVE-2026-64531?
CVE-2026-64531 is a vulnerability related to oversized nested action attributes in Open vSwitch.
When was CVE-2026-64531 published?
CVE-2026-64531 was published on July 27, 2026.