Linux kernel XDP is widely deployed; a kernel OOB bug can disrupt many systems and is high-impact across organizations.
CVE-2026-64355
Kernel OOB via cloned fragmented XDP frames in devmap (network packet path).
Is CVE-2026-64355 being exploited?
Not confirmed. CVE-2026-64355 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.51% probability of exploitation in the next 30 days.
How severe is CVE-2026-64355?
CVE-2026-64355 is rated Critical with a CVSS score of 9.8. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-64355?
Yes. A fix has been recorded for CVE-2026-64355. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-64355 affect?
CVE-2026-64355 affects Linux kernel (XDP/devmap), Linux distributions with affected kernels, Network appliances using XDP. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-64355?
Install vendor kernel patches or backports; block untrusted XDP/devmap traffic until patched.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Out-of-bounds kernel memory access when cloning fragmented XDP frames; may cause kernel crash (DoS) or enable escalation to kernel compromise.
Immediate action required
- affected>= e624d4ed4aa8cc3c69d1359b0aaea539203ed266 and < 47baddc856ae7e93a565dd9deeb797999b179466
- affected>= e624d4ed4aa8cc3c69d1359b0aaea539203ed266 and < 07a4c11ee8ef4abcb39d922e9e410ae269671cdf
- affected>= e624d4ed4aa8cc3c69d1359b0aaea539203ed266 and < bccbab36ff228e0825eb85d9b0f9b8434cd0a399
- affected>= e624d4ed4aa8cc3c69d1359b0aaea539203ed266 and < c5b4f5efcb55c1af3fe44ff712d31b7fb098a831
- affected>= e624d4ed4aa8cc3c69d1359b0aaea539203ed266 and < a9bb2d9c798cb62a4050a991c27b752770c33afe
- affected>= e624d4ed4aa8cc3c69d1359b0aaea539203ed266 and < 51d07c12ca411e692c424ecdabf077f1e61a61be
- affected>= e624d4ed4aa8cc3c69d1359b0aaea539203ed266 and < aa496720618f1a6054f1c870bf10b4f6c99bf656
- affected5.14
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.