Improper locking in Linux kernel - CVE-2026-64352
Published: July 27, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper lock handling in the lpm trie implementation when sleepable BPF programs access LPM maps. A local user can trigger lockdep warnings through crafted BPF map lookup, update, or delete operations to cause a denial of service.
This issue is lockdep-only on debug kernels and can spam the console when a sleepable BPF LSM hook touches an LPM trie.
Affected software
Debian Linux
linux (Debian package)
How to mitigate CVE-2026-64352
linux (Debian package) - update to 6.12.100-1
External References
- https://git.kernel.org/stable/c/2f884d371fafea137afea504d49ee4a7c8d7985b
- https://git.kernel.org/stable/c/304ca50582f0c047370f85e13caec456f78c9fcc
- https://git.kernel.org/stable/c/57454944737f3ad9a8703aecbbb79713b513a94b
- https://git.kernel.org/stable/c/9bfdf4b81b0e56d47bc6c46c34a46638be716695
- https://git.kernel.org/stable/c/bd6ad9a6b30498d845413e863fb95c6fab3babe3
- https://git.kernel.org/stable/c/ec662a8b2cde01e76b37ccd4b992d0342299e69c
- https://git.kernel.org/stable/c/f0967d4f1ba4323a3cb7dc8fdba74dd3a8caaf04