Use-after-free in Linux kernel - CVE-2026-64582
Published: August 6, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service or execute arbitrary code.
The vulnerability exists due to use-after-free in rxe_mmap in the RDMA/rxe subsystem when processing a memory mapping request concurrently with a DESTROY_CQ ioctl. A local user can trigger a race condition to cause a denial of service or execute arbitrary code.
Exploitation requires winning a narrow race window between the mmap path and concurrent object destruction.
Affected software
How to mitigate CVE-2026-64582
External References
- https://git.kernel.org/stable/c/3525987a392536f31a484833af258971af63b24c
- https://git.kernel.org/stable/c/35744ab3d03c5fca8c1752f53fc8fc674e14c561
- https://git.kernel.org/stable/c/665fb7d22a700c66a78db0cf88c6e6a649aba9d0
- https://git.kernel.org/stable/c/e038d42cc09ca1da9d3568ce8ae062b2bfb3bc0e
- https://git.kernel.org/stable/c/e59a6aa89e0fcd1d0707832eb4654fd9ae7d31e6