---
id: CVE-2026-64576
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  nexthop: initialize extack in nh_res_bucket_migrate()

  nh_res_bucket_migrate() passes an uninitialized netlink_ext_ack to
  call_nexthop_res_bucket_notifiers()
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  nexthop: initialize extack in nh_res_bucket_migrate()

  nh_res_bucket_migrate() passes an uninitialized netlink_ext_ack to
  call_nexthop_res_bucket_notifiers(). When
  nh_n…
severity: high
cvss: 7.1
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H'
published: '2026-08-05'
updated: '2026-08-08'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-64576'
references:
  - url: 'https://git.kernel.org/stable/c/18506d7263768d76ac8e057ba55a4d9da50aad66'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/3081702ea5aca0aeed9c1ade8eadf6cde8db6b7d'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/6347c5314cee49f364aaf2e40ff15415a57a116e'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/c0936c131a71657afc635d0db2ab096d15d473e1'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/d536bf205c71f700f6de2086038c3e1d77724715'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
epss: 0.00117
epssPercentile: 0.01895
ingestedAt: '2026-08-08T20:29:49.353Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

nexthop: initialize extack in nh_res_bucket_migrate()

nh_res_bucket_migrate() passes an uninitialized netlink_ext_ack to
call_nexthop_res_bucket_notifiers(). When
nh_notifier_res_bucket_info_init() fails (e.g. the kzalloc returns
-ENOMEM), the error is propagated back before any notifier sets
extack._msg, and the error path formats the stale pointer with
pr_err_ratelimited("%s\n", extack._msg). With CONFIG_INIT_STACK_NONE
this dereferences uninitialized stack memory:

  Oops: general protection fault, probably for non-canonical address ...
  KASAN: maybe wild-memory-access in range [...]
  RIP: 0010:string (lib/vsprintf.c:730)
   vsnprintf (lib/vsprintf.c:2945)
   _printk (kernel/printk/printk.c:2504)
   nh_res_bucket_migrate (net/ipv4/nexthop.c:1816)
   nh_res_table_upkeep (net/ipv4/nexthop.c:1866)
   rtm_new_nexthop (net/ipv4/nexthop.c:3323)
   rtnetlink_rcv_msg (net/core/rtnetlink.c:7076)
   netlink_sendmsg (net/netlink/af_netlink.c:1900)
  Kernel panic - not syncing: Fatal exception

Zero-initialize extack so _msg is NULL on error paths that never set it.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
