Use-After-Free Vulnerability in Linux Kernel Affects Networking Components
CVE-2026-64554

8.8HIGH

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
27 July 2026

What is CVE-2026-64554?

In the Linux kernel, a vulnerability exists within the netfilter networking component, specifically in the br_ip6_fragment() function. Following the invocation of skb_checksum_help(), a pointer named prevhdr may get dereferenced after being left dangling due to memory reallocation. This situation can lead to a use-after-free condition, which triggers a kernel panic and poses security risks during packet processing. Addressing this vulnerability ensures the integrity and stability of network operations.

Affected Version(s)

Linux 764dd163ac922f8683b5bcd3007251ce7b26cd33 < 8c10778ec674b67a07ea042fcba64270f3f38a5a

Linux 764dd163ac922f8683b5bcd3007251ce7b26cd33 < 2731efa6364e47934c96eb69e01ea131e8af8030

Linux 764dd163ac922f8683b5bcd3007251ce7b26cd33 < 00c06ef8c018493943891a7d0ca82b71b24f3180

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.