A vulnerability described as very critical has been identified in Linux Kernel up to 6.18.38/7.1.3. Affected by this vulnerability is the function chachapoly_create of the component chacha20poly1305. Such manipulation leads to null pointer dereference.

This vulnerability is listed as CVE-2026-64314. The attack may be performed from remote. There is no available exploit.

Upgrading the affected component is recommended.