CVE-2026-64516 – Linux Kernel

CVSS 8.8 IMPORTANT Critical - Same Day Deployment

“Modern operating systems rely on thousands of components—securing each one keeps the entire platform resilient.”

This Linux kernel security update addresses 85 vulnerabilities across numerous kernel subsystems. The fixes strengthen core operating system security by resolving memory corruption, use-after-free, double-free, out-of-bounds memory access, race conditions, permission enforcement failures, authentication weaknesses, and input validation flaws. Collectively, these updates improve system stability while reducing the attack surface across networking, storage, virtualization, filesystems, and device drivers.

The update includes multiple Critical vulnerabilities with confirmed CVSS scores of 9.8 and 9.1, together with numerous High severity vulnerabilities ranging from 7.0 to 8.8. No verified real-world exploitation or public proof-of-concept activity is included for these vulnerabilities in the provided data.

CVE LIST:
CVE-2026-64188 CVE-2026-64189 CVE-2026-64191 CVE-2026-64206 CVE-2026-64208 CVE-2026-64210 CVE-2026-64216 CVE-2026-64217 CVE-2026-64218 CVE-2026-64219 CVE-2026-64221 CVE-2026-64222 CVE-2026-64223 CVE-2026-64226 CVE-2026-64232 CVE-2026-64235 CVE-2026-64243 CVE-2026-64247 CVE-2026-64251 CVE-2026-64255 CVE-2026-64257 CVE-2026-64259 CVE-2026-64260 CVE-2026-64261 CVE-2026-64265 CVE-2026-64266 CVE-2026-64268 CVE-2026-64269 CVE-2026-64276 CVE-2026-64277 CVE-2026-64279 CVE-2026-64280 CVE-2026-64281 CVE-2026-64284 CVE-2026-64286 CVE-2026-64287 CVE-2026-64293 CVE-2026-64296 CVE-2026-64298 CVE-2026-64299 CVE-2026-64300 CVE-2026-64303 CVE-2026-64304 CVE-2026-64311 CVE-2026-64312 CVE-2026-64313 CVE-2026-64315 CVE-2026-64317 CVE-2026-64318 CVE-2026-64319 CVE-2026-64320 CVE-2026-64322 CVE-2026-64323 CVE-2026-64324 CVE-2026-64333 CVE-2026-64354 CVE-2026-64355 CVE-2026-64361 CVE-2026-64364 CVE-2026-64366 CVE-2026-64367 CVE-2026-64368 CVE-2026-64372 CVE-2026-64374 CVE-2026-64375 CVE-2026-64380 CVE-2026-64382 CVE-2026-64383 CVE-2026-64384 CVE-2026-64385 CVE-2026-64386 CVE-2026-64387 CVE-2026-64389 CVE-2026-64390 CVE-2026-64391 CVE-2026-64392 CVE-2026-64393 CVE-2026-64394 CVE-2026-64396 CVE-2026-64397 CVE-2026-64398 CVE-2026-64399 CVE-2026-64400 CVE-2026-64406 CVE-2026-64408 CVE-2026-64410 CVE-2026-64434 CVE-2026-64435 CVE-2026-64437 CVE-2026-64438 CVE-2026-64439 CVE-2026-64440 CVE-2026-64441 CVE-2026-64442 CVE-2026-64443 CVE-2026-64444 CVE-2026-64445 CVE-2026-64448 CVE-2026-64450 CVE-2026-64459 CVE-2026-64467 CVE-2026-64475 CVE-2026-64490 CVE-2026-64515 CVE-2026-64516 CVE-2026-64520 CVE-2026-64522 CVE-2026-64523, CVE-2026-53264

Vulnerability Coverage by Subsystem

SMB / KSMBD

Multiple Critical and High severity fixes address SMB client and KSMBD vulnerabilities.

Resolved issues include permission bypasses, authentication and credential handling flaws, replay handling bugs, use-after-free conditions, double-free vulnerabilities, path traversal, directory query synchronization, and improper access control.

Networking

Numerous fixes harden the networking stack, including Netfilter, RMNET, Mellanox (mlx5), Qualcomm networking, RXRPC, audit, and NetFS.

Vulnerabilities include race conditions, memory corruption, buffer validation failures, and use-after-free issues.

Bluetooth

Updates resolve High severity vulnerabilities in L2CAP and BNEP.

Fixes prevent deadlocks, connection lifetime issues, use-after-free conditions, and improper connection reference handling.

Storage and Filesystems

Security fixes span FUSE, ExFAT, UDF, ISOFS, HFS/HFS+, NFS, NVMe Target, Block Layer, and AIX partition parsing.

Improvements address bounds checking, memory safety, permission validation, metadata handling, and filesystem integrity.

Virtualization

KVM for both x86 and ARM64 receives multiple High severity fixes.

Updates improve Hyper-V handling, guest state validation, vCPU management, and memory safety.

RDMA

Critical fixes correct buffer validation, memory boundary enforcement, and protocol handling within RDMA and RTRS components.

These changes prevent out-of-bounds memory access and strengthen remote data transfer security.

Cryptography

Multiple fixes improve Kerberos, ECC, QAT, CAAM, pcrypt, and Loongson crypto components.

The update resolves memory corruption, buffer validation issues, callback handling errors, and sensitive key protection weaknesses.

BPF

Critical fixes strengthen BTF validation and XDP devmap processing.

Updates prevent integer overflow, memory corruption, and invalid packet handling.

USB / HID / Input

High severity vulnerabilities affecting HID, Wacom, Synaptics, USB serial, and input drivers are addressed.

Fixes prevent stack overflows, out-of-bounds access, buffer corruption, and invalid device state handling.

I2C / SPI / Device Drivers

Multiple driver updates resolve race conditions, DMA validation failures, use-after-free bugs, and improper resource cleanup across I2C, SPI, FPGA, CPU frequency, and other hardware components.

Memory Management and Core Kernel

Core kernel improvements address SLAB allocator behavior, scheduler logic, tracing, audit subsystem synchronization, and work queue lifetime management.

These fixes improve kernel stability and eliminate several memory safety defects.

Key Details

Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.