PatchSiren cyber security CVE debrief
CVE-2026-64314 Linux CVE debrief
A vulnerability in the Linux kernel's crypto: chacha20poly1305 has been resolved. The chachapoly_create() function still accepts the compatibility poly1305 parameter in the template name but assumes the second template argument is always present. When the argument is missing, crypto_attr_alg_name() returns an error pointer. Check for that before comparing the name so malformed template instantiations fail with an error instead of dereferencing the error pointer in strcmp().
- Vendor
- Linux
- Product
- Unknown
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-25
- Original CVE updated
- 2026-09-03
- Advisory published
- 2026-07-25
- Advisory updated
- 2026-09-03
Who should care
Linux kernel maintainers, Linux distribution maintainers, and users of Linux kernel versions 6.16 through 6.18.39 and 6.19 through 7.1.4 should assess exposure and verify patch deployment.
Why it matters
CVE-2026-64314 is a vulnerability in the Linux kernel's crypto: chacha20poly1305 that can cause crashes or errors if exploited. Linux kernel maintainers and users should assess exposure and verify patch deployment to prevent potential impacts.
- Verify patch deployment for affected Linux kernel versions to prevent potential crashes or errors
- Assess exposure of Linux kernel deployments to CVE-2026-64314 to prioritize patching
- Monitor Linux kernel updates for potential future vulnerabilities related to crypto: chacha20poly1305
Technical summary
The chachapoly_create() function in the Linux kernel's crypto: chacha20poly1305 accepts a compatibility poly1305 parameter in the template name but assumes the second template argument is always present. When the argument is missing, crypto_attr_alg_name() returns an error pointer. Check for that before comparing the name so malformed template instantiations fail with an error instead of dereferencing the error pointer in strcmp().
Defensive priority
Linux kernel maintainers and users should assess exposure and verify patch deployment.
Recommended defensive actions
- Assess exposure of Linux kernel deployments to CVE-2026-64314
- Verify patch deployment for affected Linux kernel versions
- Monitor Linux kernel updates for potential future vulnerabilities
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and NVD entry provide details on the vulnerability and patches. Linux kernel maintainers and users are advised to verify patch deployment. The vulnerability affects Linux kernel versions 6.16 through 6.18.39 and 6.19 through 7.1.4. The patches address the issue by validating the poly1305 template argument in the chachapoly_create() function. Evidence from the CVE record and NVD entry suggests that the vulnerability can cause crashes or errors if exploited. Defenders should verify patch deployment for affected Linux
Sources and references
Verified primary and authoritative sources
-
CVE-2026-64314 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-64314
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-64314 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-64314
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/0016d3c21c6ab60a20be7f565cefb5999f3adeb6
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/265b861bece38318b8e0fc8fac0643d4ef906d31
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/e74df53b36cdc6b6b9e5488ec883d1d55624737f
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.