Use-after-free in Linux kernel - CVE-2026-64459
Published: July 27, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in the TCP-AO socket destruction logic when processing crafted TCP-AO traffic during connect(). A local user can send crafted network segments and trigger connect() to cause a denial of service.
Exploitation requires the ability to configure TCP_MD5SIG and TCP_AO keys on a socket.