A vulnerability was found in Linux Kernel up to 7.1.5/7.2-rc3. It has been declared as very critical. The impacted element is the function xfrm_user_policy of the file net/xfrm/xfrm_state.c of the component xfrm. Executing a manipulation can lead to double free.

This vulnerability is registered as CVE-2026-64581. It is possible to launch the attack remotely. No exploit is available.

It is recommended to upgrade the affected component.