Use-after-free in Linux kernel - CVE-2026-64560
Published: July 30, 2026
Vulnerability details
The vulnerability allows a local user to execute arbitrary code.
The vulnerability exists due to a use-after-free in the posix CPU timers subsystem when handling a non-leader exec() race involving POSIX CPU timer deletion, setting, or rearming. A local user can trigger concurrent exec() and timer operations to execute arbitrary code.
The issue occurs when a TGID-targeted timer remains inherited across exec(), and can also cause user-visible transient -ESRCH errors or prevent timer rearming.
Affected software
Debian Linux
linux (Debian package)
How to mitigate CVE-2026-64560
linux (Debian package) - update to 6.12.100-1