Kernel network driver UAF in ixgbevf affects SR-IOV VFs used widely in virtualized/cloud hosts; can crash or enable kernel-level compromise across infrastructure.
CVE-2026-64113
Use-after-free in ixgbevf driver may cause kernel crash or allow kernel RCE via crafted network frames.
Is CVE-2026-64113 being exploited?
Not confirmed. CVE-2026-64113 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.55% probability of exploitation in the next 30 days.
How severe is CVE-2026-64113?
CVE-2026-64113 is rated Critical with a CVSS score of 9.8. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-64113?
Yes. A fix has been recorded for CVE-2026-64113. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-64113 affect?
CVE-2026-64113 affects Linux kernel (ixgbevf driver), SR-IOV virtual functions (Intel ixgbe family), Virtualized hosts using VF passthrough. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-64113?
Install vendor/kernel update and reboot hosts; restrict untrusted VF or multicast traffic if patch delayed.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Crafted VEPA multicast frames can trigger a use-after-free in ixgbevf, leading to kernel crash or potential kernel-level code execution from network/VM attack surface.
Immediate action required
- affected>= bad17234ba702a50aeec50ab04724ee58af89607 and < 3d931ac62411a7e43b85dba5fe45e1a4a91bd5cb
- affected>= bad17234ba702a50aeec50ab04724ee58af89607 and < 6ef30384a50a50e4a484cddf341bc27de31aa3de
- affected>= bad17234ba702a50aeec50ab04724ee58af89607 and < 55b3e91d62b2f7a24109b2d7c9f4c66d2e3b1ec1
- affected>= bad17234ba702a50aeec50ab04724ee58af89607 and < add70e2682c0ad3be2a5810bcf1bc13963ba4df9
- affected>= bad17234ba702a50aeec50ab04724ee58af89607 and < a244395d8c563ed1bb26c3ef708db6aeeaa08084
- affected>= bad17234ba702a50aeec50ab04724ee58af89607 and < dfef79e09ed2f5df975c98547f97f5d7f8982a24
- affected>= bad17234ba702a50aeec50ab04724ee58af89607 and < e8768bcbe5cd30c4ea36a22022c9ffaa66903693
- affected>= bad17234ba702a50aeec50ab04724ee58af89607 and < 5d49b568c188dc77199d8d2b959c91da8cc27cf1
- affected3.19
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.