Use-after-free in Linux kernel - CVE-2026-64543
Published: July 28, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to use-after-free in tipc_disc_rcv() when processing TIPC discovery messages on a UDP bearer. A local user can trigger network namespace-accessible TIPC bearer operations and send crafted traffic to cause a denial of service.
Exploitation requires CONFIG_TIPC and CONFIG_TIPC_MEDIA_UDP. The affected functionality is reachable from an unprivileged user namespace because the TIPCv2 generic netlink family is netnsok and its bearer commands do not require GENL_ADMIN_PERM.
Affected software
Debian Linux
linux (Debian package)
How to mitigate CVE-2026-64543
linux (Debian package) - update to 6.12.100-1
External References
- https://git.kernel.org/stable/c/1579342d71133da7f00daa02c75cebec7372097b
- https://git.kernel.org/stable/c/5e215bf1c47fdddf8203a0fe80a0ed594065f101
- https://git.kernel.org/stable/c/a0c5fdeb5fa257f8c6d469af266bc087cb5de6a2
- https://git.kernel.org/stable/c/b65289e1c3f352a9f92c6e19713ddd647e033253
- https://git.kernel.org/stable/c/ec7d54d8cc1723921d671e3272b427c96366506f