Out-of-bounds write in Linux kernel - CVE-2026-64304

 

Out-of-bounds write in Linux kernel - CVE-2026-64304

Published: July 27, 2026


Vulnerability identifier: #VU139674
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-64304
CWE-ID: CWE-787
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to cause memory corruption.

The vulnerability exists due to an out-of-bounds write in qat_rsa_setkey_crt() when processing RSA CRT key components larger than half of the key size. A local user can provide a crafted RSA CRT key to cause memory corruption.

The issue occurs because CRT components are bounded by the modulus size in the generic RSA key parser, while the QAT driver allocates half-size DMA buffers for those components.


Affected software

Linux kernel

How to mitigate CVE-2026-64304

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3

External References

Related Security Bulletins