Use-After-Free Vulnerability in Linux Kernel Affecting Memory Management
CVE-2026-64563
What is CVE-2026-64563?
A vulnerability exists within the Linux kernel related to the handling of rhashtable during memory management processes. Specifically, when iterating through rhashtable, there are circumstances where stale pointers are not cleared adequately on table restarts. This oversight can lead to dereferencing a freed memory location, which may cause instability and crashes in systems that rely on multi-fragment rhashtable walks. Notable operations affected by this vulnerability include netlink_diag and TIPC, posing a risk to system integrity and security protocols.
Affected Version(s)
Linux 5d240a8936f6a1d3ece06701e8c4d830a2eca8a8 < 3ff7c1dbf722cf3fa538672452ba182318e0fcc3
Linux 5d240a8936f6a1d3ece06701e8c4d830a2eca8a8 < 4169d9fb92f313ff8e7e83d733c1ecdcc93eebd3
Linux 5d240a8936f6a1d3ece06701e8c4d830a2eca8a8 < 8173f7e2ce67e6ca1d4763f3da14e5b01ce77456