🟡 Medium  |  Source: Microsoft Security Response Center


CVE-2026-64576 is a Linux kernel vulnerability affecting the nexthop routing subsystem, specifically a failure to properly initialise the extended acknowledgement (extack) structure in the nh_res_bucket_migrate() function. This could lead to uninitialised memory being accessed or exposed during network routing operations. While details remain sparse at time of publication, kernel-level networking flaws can affect Azure infrastructure and workloads running Linux-based virtual machines.

Security Architect’s Take: Review whether your Azure Linux VMs or AKS node pools are running kernel versions affected by this flaw and prioritise patching via Azure Update Manager or your distribution’s package manager. Monitor the MSRC advisory page for a CVSS score and exploit status as further details are published.

Original advisory: CVE-2026-64576 nexthop: initialize extack in nh_res_bucket_migrate()