CVE-2026-64033
Use-after-free in Linux RDMA rtrs can crash kernel or enable privilege escalation.
Is CVE-2026-64033 being exploited?
Not confirmed. CVE-2026-64033 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.49% probability of exploitation in the next 30 days.
How severe is CVE-2026-64033?
CVE-2026-64033 is rated Critical with a CVSS score of 9.8. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-64033?
Yes. A fix has been recorded for CVE-2026-64033. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-64033 affect?
CVE-2026-64033 affects Linux kernel (RDMA/rtrs subsystem), Distributions with RDMA enabled (Ubuntu/RHEL/SUSE/Debian), Kernels with rtrs/rdma modules enabled. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-64033?
Apply vendor kernel patches or upgrade to a patched kernel; restrict RDMA access until patched.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Attackers with RDMA/rtrs access can trigger a kernel use-after-free, causing crashes, potential privilege escalation or kernel code execution.
Patch when possible
- affected>= bab17b761c8974a869b04462be5d4dd9aad366b4 and < 01e42aabaf7632beb4bf235c7238b96c746d4144
- affected>= ae4c81644e9105d9f7f713bb0d444737bb6a0cf1 and < 548f3956e53a7f7bde912d8129010b8986d5e602
- affected>= ae4c81644e9105d9f7f713bb0d444737bb6a0cf1 and < 00904a73272b9f3ef3952fe69a833909dccad1ef
- affected>= ae4c81644e9105d9f7f713bb0d444737bb6a0cf1 and < 92060ab1c5115674cf319175550f85f68405121f
- affected>= ae4c81644e9105d9f7f713bb0d444737bb6a0cf1 and < eae62c5451e67e8b033c1681fd3b85d7e9a9a28f
- affected>= ae4c81644e9105d9f7f713bb0d444737bb6a0cf1 and < b0e9706fb2859064bb6c677554c4d20c713aa8e0
- affected>= ae4c81644e9105d9f7f713bb0d444737bb6a0cf1 and < 5b74373390113fba798a76b483837029ab010fef
- affected>= 5.15.61 and < 5.15.209
- affected5.17
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.