Out-of-bounds Access Vulnerability in Linux Kernel Affecting CPU Offlining
CVE-2026-64477

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
25 July 2026

What is CVE-2026-64477?

A vulnerability exists within the Linux Kernel where an out-of-bounds access can occur during the offlining of CPUs when SNC (Scale-Out Non-Uniform Memory Access) is enabled. As the architecture updates the cpu_mask in a domain's header to monitor online CPUs, issues arise when the cpu_mask becomes empty. This action prompts the architecture to initiate the offlining process, inadvertently leading to a scenario where the NUMA (Non-Uniform Memory Access) node ID is queried with an incorrect argument, causing the out-of-bounds access. The limbo handler is adjusted to circumvent unnecessary RMID reads when the RMID is ensured to be cleared and further safety checks are added to protect the RMID reader, enhancing the overall security of the system.

Affected Version(s)

Linux e13db55b5a0d447dea63cde772c1078405bbbf96

Linux e13db55b5a0d447dea63cde772c1078405bbbf96

Linux e13db55b5a0d447dea63cde772c1078405bbbf96 < 58c5ec23b1a238eb75cb0aba6f69d8f9e68ef0b2

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.