CVE-2026-64574 – Linux Kernel
“Critical memory and networking flaws can turn routine kernel operations into crashes, corruption, and unsafe memory access.”
Linux kernel updates resolve 26 vulnerabilities across SCTP, SMB, KVM, Wi-Fi, Btrfs, BPF, XFRM, RDMA, USB, networking, FUSE, and cryptographic components. CVE-2026-64564, CVE-2026-64566, and CVE-2026-64597 each have a CVSS score of 9.8, Critical severity. The remaining vulnerabilities range from CVSS 7.0 to 8.8, all High severity.
CVE List:
CVE-2026-64564 (9.8)
CVE-2026-64566 (9.8)
CVE-2026-64597 (9.8)
CVE-2026-64561 (8.8)
CVE-2026-64562 (8.8)
CVE-2026-64578 (8.2)
CVE-2026-64586 (8.8)
CVE-2026-64598 (8.8)
CVE-2026-64563 (7.8)
CVE-2026-64567 (7.8)
CVE-2026-64568 (7.8)
CVE-2026-64570 (7.8)
CVE-2026-64574 (7.8)
CVE-2026-64575 (7.8)
CVE-2026-64576 (7.1)
CVE-2026-64577 (7.5)
CVE-2026-64580 (7.8)
CVE-2026-64581 (7.8)
CVE-2026-64582 (7.8)
CVE-2026-64583 (7.8)
CVE-2026-64584 (7.8)
CVE-2026-64585 (7.8)
CVE-2026-64587 (7.0)
CVE-2026-64588 (7.8)
CVE-2026-64599 (7.8)
CVE-2026-64601 (7.8)
The flaws include use-after-free, double-free, out-of-bounds access, race conditions, memory corruption, invalid pointer handling, and kernel panic conditions. Updated Linux kernel releases contain fixes that strengthen memory lifetime, bounds checking, synchronization, and error handling across the affected subsystems.
Three vulnerabilities carry 9.8 Critical severity scores.
The update fixes numerous kernel memory-safety and resource-lifetime weaknesses.
Several flaws can cause memory corruption, use-after-free conditions, or kernel panics.
Fixes span networking, virtualization, storage, wireless, USB, and other kernel subsystems.
Key Details
- Attack Vector
- Local
- Attack Complexity
- Low
- Privileges Required
- Low
- User Interaction
- None