xfrm6_fill_dst of the file net/ipv6/xfrm6_policy.c of the component xfrm6. The manipulation leads to double free.This vulnerability is documented as CVE-2026-64580. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is advised.