Kernel-level IPv6 vulnerability in widely deployed Linux kernels; can crash or compromise hosts across enterprises and infrastructure.
CVE-2026-64132
Linux kernel IPv6 ioam use-after-free allows kernel memory corruption via crafted packets.
Is CVE-2026-64132 being exploited?
Not confirmed. CVE-2026-64132 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.49% probability of exploitation in the next 30 days.
How severe is CVE-2026-64132?
CVE-2026-64132 is rated Critical with a CVSS score of 9.8. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-64132?
Yes. A fix has been recorded for CVE-2026-64132. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-64132 affect?
CVE-2026-64132 affects Linux kernel (ipv6 ioam enabled). Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-64132?
Apply vendor kernel patches or disable IPv6 IOAM; block malformed IPv6 until patched.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Remote use-after-free in IPv6 ioam leading to kernel memory corruption, crash, or possible RCE/privilege escalation via crafted packets.
Immediate action required
- affected>= f655c78d6225f585ef60a9d93ffb79d507ff3ad3 and < 769723124b7c3b2bfea4cf68ad292698b87c8d01
- affected>= f655c78d6225f585ef60a9d93ffb79d507ff3ad3 and < 24de676da63c1122d2c13b0d546238b66d1b4e62
- affected>= f655c78d6225f585ef60a9d93ffb79d507ff3ad3 and < 5af905aa8e91ff8d94572a1e089558f21dcf24ed
- affected>= f655c78d6225f585ef60a9d93ffb79d507ff3ad3 and < e46e6bc97fb1f339730ff1ba74267fbf48e7a422
- affected6.9
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.