Out-of-bounds read in Linux kernel - CVE-2026-64243
Published: July 27, 2026
Vulnerability identifier: #VU139749
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2026-64243
CWE-ID: CWE-125
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vendor: Linux Foundation
Affected software:
Linux kernel
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in simple_mux_control_put() when processing enumerated control values. A local user can supply an invalid enumerated item value to trigger an out-of-bounds read and cause a denial of service.
How to mitigate CVE-2026-64243
Install security update from vendor's repository.
Sources
- https://git.kernel.org/stable/c/05ef77f02607a3dc5d7f9762cb990f76843315d4
- https://git.kernel.org/stable/c/164dcbec9632ca93ae313e6da6e4e05584fa0f02
- https://git.kernel.org/stable/c/2ff3ac6f7664fe5639cad01712ac5e021fa7939c
- https://git.kernel.org/stable/c/5fe860af8630cf7c78523cbd68e5a234743585aa
- https://git.kernel.org/stable/c/6fb653b62f169f6050fac45b56bf21ad097e19f6
- https://git.kernel.org/stable/c/d8cc3e747b002a8b965c529de79c0654675b9a1a
- https://git.kernel.org/stable/c/f63ad68e18d774a5d15cd7e405ead63f6b322679