CVE-2026-64235
Linux x86 ftrace dynamic trampolines can cause kernel panic (local DoS).
Is CVE-2026-64235 being exploited?
Not confirmed. CVE-2026-64235 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.33% probability of exploitation in the next 30 days.
How severe is CVE-2026-64235?
CVE-2026-64235 is rated High with a CVSS score of 8.1. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-64235?
Yes. A fix has been recorded for CVE-2026-64235. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-64235 affect?
CVE-2026-64235 affects Linux kernel on x86, Systems built with CONFIG_CALL_DEPTH_TRACKING, Platforms with retbleed=stuff (e.g., Skylake). Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-64235?
Install the kernel patch; restrict access to /sys/kernel/tracing until patched.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Local user with tracing access can trigger a page fault and kernel panic via ftrace dynamic trampolines, causing host crash/denial of service.
Patch when possible
- affected>= 59bec00ace28d565ae0a68b23063ef3b961d82d5 and < 8093442a2d1d4b42b9340a86023ccb2afb30b93a
- affected>= 59bec00ace28d565ae0a68b23063ef3b961d82d5 and < d59cc66b702757e3c5a711e78a38583eac0c2738
- affected>= 59bec00ace28d565ae0a68b23063ef3b961d82d5 and < 9edff632ca216169846f8a63a5a3dc467e239c7a
- affected>= 59bec00ace28d565ae0a68b23063ef3b961d82d5 and < a17dc12bfed8868e6a86f3b45c16065a70641acb
- affected6.9
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.