Linux kernel vuln affecting BPF/ktls in widely deployed OS kernels; can crash or enable kernel-level compromise across servers and devices—newsworthy and enterprise-impacting.
CVE-2026-64025
Linux kernel use-after-free in BPF + KTLS skmsg verdict path causing kernel crash/RCE risk.
Is CVE-2026-64025 being exploited?
Not confirmed. CVE-2026-64025 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.44% probability of exploitation in the next 30 days.
How severe is CVE-2026-64025?
CVE-2026-64025 is rated Critical with a CVSS score of 9.8. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-64025?
Yes. A fix has been recorded for CVE-2026-64025. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-64025 affect?
CVE-2026-64025 affects Linux kernel (BPF, skmsg, ktls), Any distro kernels integrating the fix required. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-64025?
Apply vendor kernel patch immediately; block untrusted eBPF and restrict ktls/sockmap until patched.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Use-after-free in kernel networking stack can crash the kernel (DoS) or enable kernel code execution/privilege escalation via crafted BPF/socket traffic.
Immediate action required
- affected>= ef5659280eb13e8ac31c296f58cfdfa1684ac06b and < c9ea01768903ae47f210cd457af1dead6de7a9c3
- affected>= ef5659280eb13e8ac31c296f58cfdfa1684ac06b and < 7c8cf21bc4efb4af18d6096db3f8bd06d622251c
- affected>= ef5659280eb13e8ac31c296f58cfdfa1684ac06b and < 1861d369efd62d67796563bf3e01fc22e5626f8b
- affected>= ef5659280eb13e8ac31c296f58cfdfa1684ac06b and < 8a52139560f833c3975032e1f5762611e3a36d71
- affected>= ef5659280eb13e8ac31c296f58cfdfa1684ac06b and < ddf8029623a1af20e984c040e89ff918158397ab
- affected5.10
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.