CVE-2026-64010
Use-after-free in Linux kernel NFC LLCP allowing local kernel memory corruption.
Is CVE-2026-64010 being exploited?
Not confirmed. CVE-2026-64010 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.26% probability of exploitation in the next 30 days.
How severe is CVE-2026-64010?
CVE-2026-64010 is rated High with a CVSS score of 8.8. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-64010?
Yes. A fix has been recorded for CVE-2026-64010. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-64010 affect?
CVE-2026-64010 affects Linux kernel NFC LLCP subsystem, Linux distributions with vulnerable kernels, Android devices with vulnerable kernels, NFC-enabled IoT/embedded devices. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-64010?
Apply kernel updates or backported patches; disable NFC until patched.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Local NFC attacker can trigger use-after-free causing kernel memory corruption, crash (DoS) or potential local privilege escalation.
Patch when possible
- affected>= a69f32af86e389dd232b1bb2269e202c1bfcc60f and < dce85215a6c7b0fd753f577a4c487f647119884c
- affected>= a69f32af86e389dd232b1bb2269e202c1bfcc60f and < bd08bb7443c501d2f2a71d529e4afcf11c9b07d2
- affected>= a69f32af86e389dd232b1bb2269e202c1bfcc60f and < 0b45c31746e1523d5d482fda8fcf54a35ac417f1
- affected>= a69f32af86e389dd232b1bb2269e202c1bfcc60f and < ee2d1a8a1833c5e56e9a1745e64b0b4edda732c2
- affected>= a69f32af86e389dd232b1bb2269e202c1bfcc60f and < ad8a27d63cac96bac441edd002209ebd996e12fb
- affected>= a69f32af86e389dd232b1bb2269e202c1bfcc60f and < 650bdd8fdfab64a09ee474150313dbc48c374795
- affected>= a69f32af86e389dd232b1bb2269e202c1bfcc60f and < b2a60f7f846faaf5c2cdad4ea6d3a33e5f863183
- affected>= a69f32af86e389dd232b1bb2269e202c1bfcc60f and < b493ea2765cc17cb8aa7e7544a4b6dcb05b6ed77
- affected3.6
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.