Use-after-free in Linux kernel - CVE-2026-64249
Published: July 27, 2026
Vulnerability identifier: #VU139740
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-64249
CWE-ID: CWE-416
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to use-after-free in child_regions_with_firmware() in drivers/fpga/of-fpga-region.c when handling child FPGA region data. A local user can trigger the error path to cause a denial of service.
Affected software
Linux kernel
How to mitigate CVE-2026-64249
Install security update from vendor's repository.
Linux kernel - update to 7.0 rc3
External References
- https://git.kernel.org/stable/c/070b0ce947b18fa3dec0729695147f7e19599649
- https://git.kernel.org/stable/c/369496d885b4cf6e8647cf4dc5cf3ac68fdf37a1
- https://git.kernel.org/stable/c/54f3c5643ec523a04b6ec0e7c19eb10f5ebebdd3
- https://git.kernel.org/stable/c/5e098e40e8bac43ed58645c10d5fad781966efe4
- https://git.kernel.org/stable/c/866184fc7ae42a0070f1141ae8c5dca7c24a59e2
- https://git.kernel.org/stable/c/e79afcb0a66d2b3c33e510eade902537e656fc00
- https://git.kernel.org/stable/c/e918942bcc5355ad5b44ba557935dffc0727b0eb
- https://git.kernel.org/stable/c/fbaf509ad7cb2f7dafe73ca20c956104cfcc9d68