CVE-2026-64247
KVM guest-supplied VP ID causes out-of-bounds read, risking host crash or memory leak.
Is CVE-2026-64247 being exploited?
Not confirmed. CVE-2026-64247 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.11% probability of exploitation in the next 30 days.
How severe is CVE-2026-64247?
CVE-2026-64247 is rated High with a CVSS score of 8.4. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-64247?
Yes. A fix has been recorded for CVE-2026-64247. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-64247 affect?
CVE-2026-64247 affects Linux kernel KVM, kvm_intel module, Enlightened VMCS (Hyper-V guests), QEMU/KVM hosts. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-64247?
Upgrade Linux kernels to the patched KVM release and restrict untrusted guests until updated.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Guest-crafted VP ID triggers OOB read/use-after-free in KVM, allowing host memory disclosure, host crash, or potential VM escape/DoS.
Immediate action required
- affected>= c58a318f6090efe06e6702b8882e2026f44f620e and < d18756b12aab30d07794446445c93112e5c69a2e
- affected>= c58a318f6090efe06e6702b8882e2026f44f620e and < 83c2f52c6a78b1590034e955cff3fe0b052fe4ae
- affected>= c58a318f6090efe06e6702b8882e2026f44f620e and < e36095d8d922bb26ce860231aacf0cd14edea07c
- affected>= c58a318f6090efe06e6702b8882e2026f44f620e and < f636cf6a1e7b7f40d48d8d08bd5f152aa61dd130
- affected>= c58a318f6090efe06e6702b8882e2026f44f620e and < 4721f8160f17554b003e8928bb61e6c9b2fe92a3
- affected6.2
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.