SB20260720208 - Use-after-free in Linux kernel core
Published: July 20, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Use-after-free (CVE-ID: CVE-2026-64025)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service or execute arbitrary code.
The vulnerability exists due to a use-after-free in sk_psock_verdict_data_ready in the Linux kernel BPF sockmap/skmsg handling when processing socket data with a TLS RX context present. A local user can trigger the race condition to cause a denial of service or execute arbitrary code.
Exploitation requires a socket to be inserted into a sockmap before TLS RX is configured.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/1861d369efd62d67796563bf3e01fc22e5626f8b
- https://git.kernel.org/stable/c/7c8cf21bc4efb4af18d6096db3f8bd06d622251c
- https://git.kernel.org/stable/c/8a52139560f833c3975032e1f5762611e3a36d71
- https://git.kernel.org/stable/c/c9ea01768903ae47f210cd457af1dead6de7a9c3
- https://git.kernel.org/stable/c/ddf8029623a1af20e984c040e89ff918158397ab