CVE-2026-64268
Linux kernel siw RDMA out-of-bounds write via crafted Read Response segments
Is CVE-2026-64268 being exploited?
Not confirmed. CVE-2026-64268 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.71% probability of exploitation in the next 30 days.
How severe is CVE-2026-64268?
CVE-2026-64268 is rated Critical with a CVSS score of 9.8. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-64268?
Yes. A fix has been recorded for CVE-2026-64268. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-64268 affect?
CVE-2026-64268 affects Linux kernel (drivers/infiniband/sw/siw), Systems using SoftiWARP/siw iWARP over TCP, RDMA-enabled Linux servers. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-64268?
Install vendor kernel updates; restrict/block siw/iWARP traffic and untrusted RDMA peers until patched.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Remote kernel memory corruption from a connected RDMA/iWARP peer leading to privilege escalation, possible RCE or kernel crash.
Immediate action required
- affected>= 8b6a361b8c482f22ac99c3273285ff16b23fba91 and < a31b6d18ded3cc32d9ee85a6ff0726d4274887b2
- affected>= 8b6a361b8c482f22ac99c3273285ff16b23fba91 and < 595e6537ad1a210da32cbb9a7f91aa73090915ba
- affected>= 8b6a361b8c482f22ac99c3273285ff16b23fba91 and < 3ef7e052cbd05a8b13a51a07b185a39ec93ee1cf
- affected>= 8b6a361b8c482f22ac99c3273285ff16b23fba91 and < b2e26c955f8dd7e8d3f16c858db05245ea4fa817
- affected>= 8b6a361b8c482f22ac99c3273285ff16b23fba91 and < 6bc89f34a4597f9f6d41f7a60c67a3153bfe8851
- affected>= 8b6a361b8c482f22ac99c3273285ff16b23fba91 and < 423a78ff7928c2601013f73ec6d896f5597d0df5
- affected>= 8b6a361b8c482f22ac99c3273285ff16b23fba91 and < 75c93cd3c421890f49ea93f0b978b9b7bb10e5e3
- affected>= 8b6a361b8c482f22ac99c3273285ff16b23fba91 and < 7d29f7e9dbd844cae4d3e559cf78324b9642fd6b
- affected5.3
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.