DEBIAN-CVE-2026-64566
In the Linux kernel, the following vulnerability has been resolved: xfrm: iptfs: propagate SKBFLSHAREDFRAG in iptfsskbaddfrags() When iptfsskbaddfrags() copies frag references from the source frag walk into a new SKB, it increments the page reference count via skbfragref() but does not propagate SKBFLSHAREDFRAG to the destination SKB's skbshinfo->flags. If the source SKB carries shared frags (e.g. from a page-pool backed receive path), the new inner SKB will appear to ESP as having privately owned frags. A subsequent espinput() call for a nested transport-mode SA then takes the no-COW fast path and decrypts in place, writing over pages that are still referenced by the outer IPTFS SKB. This causes kernel-visible memory corruption and can trigger a panic. All other frag-transfer helpers in the kernel (skbtrycoalesce, skbgroreceive, pskbcopyfclone, skbshift, skbsegment) correctly propagate SKBFLSHAREDFRAG; align iptfsskbaddfrags() with this convention by setting the flag inside the loop immediately after skbfragref() and nrfrags++, so every exit path that attaches a frag unconditionally propagates SKBFLSHAREDFRAG.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://security-tracker.debian.org/tracker/CVE-2026-64566