Use-after-free in Linux kernel - CVE-2026-64025
Published: July 20, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service or execute arbitrary code.
The vulnerability exists due to a use-after-free in sk_psock_verdict_data_ready in the Linux kernel BPF sockmap/skmsg handling when processing socket data with a TLS RX context present. A local user can trigger the race condition to cause a denial of service or execute arbitrary code.
Exploitation requires a socket to be inserted into a sockmap before TLS RX is configured.
How to mitigate CVE-2026-64025
Sources
- https://git.kernel.org/stable/c/1861d369efd62d67796563bf3e01fc22e5626f8b
- https://git.kernel.org/stable/c/7c8cf21bc4efb4af18d6096db3f8bd06d622251c
- https://git.kernel.org/stable/c/8a52139560f833c3975032e1f5762611e3a36d71
- https://git.kernel.org/stable/c/c9ea01768903ae47f210cd457af1dead6de7a9c3
- https://git.kernel.org/stable/c/ddf8029623a1af20e984c040e89ff918158397ab