Race condition in Linux kernel - CVE-2026-64506

 

Race condition in Linux kernel - CVE-2026-64506

Published: July 27, 2026


Vulnerability identifier: #VU139432
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-64506
CWE-ID: CWE-362
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper state management in the rtw89 wifi driver AMPDU frame handling logic when processing malformed AMPDU frames. A remote attacker can send malformed AMPDU frames to cause a denial of service.

It is more likely to be triggered during busy traffic conditions while pairwise rekey is in progress, and may cause disconnection from the access point.


Affected software

Linux kernel

How to mitigate CVE-2026-64506

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3

External References

Related Security Bulletins