Use-After-Free Vulnerability in Linux Kernel Affecting Memory Management
CVE-2026-64563

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
4 August 2026

What is CVE-2026-64563?

A vulnerability exists within the Linux kernel related to the handling of rhashtable during memory management processes. Specifically, when iterating through rhashtable, there are circumstances where stale pointers are not cleared adequately on table restarts. This oversight can lead to dereferencing a freed memory location, which may cause instability and crashes in systems that rely on multi-fragment rhashtable walks. Notable operations affected by this vulnerability include netlink_diag and TIPC, posing a risk to system integrity and security protocols.

Affected Version(s)

Linux 5d240a8936f6a1d3ece06701e8c4d830a2eca8a8 < 3ff7c1dbf722cf3fa538672452ba182318e0fcc3

Linux 5d240a8936f6a1d3ece06701e8c4d830a2eca8a8 < 4169d9fb92f313ff8e7e83d733c1ecdcc93eebd3

Linux 5d240a8936f6a1d3ece06701e8c4d830a2eca8a8 < 8173f7e2ce67e6ca1d4763f3da14e5b01ce77456

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.