CVE-2026-64118
Double-free in Linux qed driver may crash kernel or enable local escalation.
Is CVE-2026-64118 being exploited?
Not confirmed. CVE-2026-64118 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.15% probability of exploitation in the next 30 days.
How severe is CVE-2026-64118?
CVE-2026-64118 is rated High with a CVSS score of 8.4. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-64118?
Yes. A fix has been recorded for CVE-2026-64118. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-64118 affect?
CVE-2026-64118 affects Linux kernel (qed driver), Systems with Broadcom/Marvell QLogic NICs using qed. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-64118?
Update kernel to a release containing the qed fix or apply vendor NIC driver updates and reboot.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Local double-free in qed driver can crash the kernel (DoS) and, with device-specific conditions, enable local privilege escalation or arbitrary kernel code execution.
Patch when possible
- affected>= fe56b9e6a8d957d6a20729d626027f800c17a2da and < 9fe030719bd083b766602692ee96c8c985798e3c
- affected>= fe56b9e6a8d957d6a20729d626027f800c17a2da and < 06fa8e69019fd3c41a7b0ea8c5f509c3a33dc227
- affected>= fe56b9e6a8d957d6a20729d626027f800c17a2da and < 8cf5e4d2ca6b101d163c7423a426fb0aec34f7bb
- affected>= fe56b9e6a8d957d6a20729d626027f800c17a2da and < 3904b993cc17ec5d7c5d3b57dbd0b775dafb9684
- affected>= fe56b9e6a8d957d6a20729d626027f800c17a2da and < bdf678a273cadbccc347f331ae2e93ff4d14834c
- affected>= fe56b9e6a8d957d6a20729d626027f800c17a2da and < 0e47fc1c9181ae029e0e35a865cbf2adcbae626c
- affected>= fe56b9e6a8d957d6a20729d626027f800c17a2da and < a04c207f0801abdd23a169b5f902a9845059a65a
- affected>= fe56b9e6a8d957d6a20729d626027f800c17a2da and < 2bccfb8476ca5f3548afbd623dc7a6980d4e77de
- affected4.4
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.