Use-after-free in Linux kernel - CVE-2026-64286

 

Use-after-free in Linux kernel - CVE-2026-64286

Published: July 27, 2026


Vulnerability identifier: #VU139698
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-64286
CWE-ID: CWE-416
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper handling of a stale pointer in flush_hyp_vcpu() when copying the host vCPU context into the hyp private vCPU. A local user can provide a crafted __hyp_running_vcpu value to cause a denial of service.

The issue occurs on arm64 KVM with pKVM at EL2 during vCPU context handling.


Affected software

Linux kernel
Debian Linux
Ubuntu
linux (Debian package)
linux (Ubuntu package)
linux-gcp-7.0 (Ubuntu package)
linux-oem-7.0 (Ubuntu package)

How to mitigate CVE-2026-64286

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3
linux (Debian package) - update to 6.12.100-1
linux (Ubuntu package) - addressed in versions 7.0.0-31.31, 7.0.0-31.31.1, 7.0.0-31.31~24.04.1, 7.0.0-1006.7, 7.0.0-1011.11~24.04.1, 7.0.0-1012.12, 7.0.0-1012.12~24.04.1
linux-gcp-7.0 (Ubuntu package) - update to 7.0.0-1011.11~24.04.1
linux-oem-7.0 (Ubuntu package) - update to 7.0.0-1013.13

External References

Related Security Bulletins