CVE-2026-64364
Linux kernel multitouch OOB bit access allows kernel panic/DoS via malicious HID devices
Is CVE-2026-64364 being exploited?
Not confirmed. CVE-2026-64364 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.35% probability of exploitation in the next 30 days.
How severe is CVE-2026-64364?
CVE-2026-64364 is rated High with a CVSS score of 8.8. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-64364?
Yes. A fix has been recorded for CVE-2026-64364. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-64364 affect?
CVE-2026-64364 affects Linux kernel (input/multitouch), Devices with USB/Bluetooth HID multitouch (touchpads/touchscreens), Android devices using vulnerable kernels. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-64364?
Apply kernel update; block/untrusted HID devices; restrict USB/Bluetooth until patched
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Malicious USB/Bluetooth multitouch device can corrupt kernel memory causing remote kernel panic (DoS); memory corruption may enable privilege escalation.
Patch when possible
- affected>= fc488f675344931ffab6a51c43691065ec006567 and < 12e90656e330ff8bbaf2f29c535fdb8a11cc6f55
- affected>= 77711d850bed75ae7142c3d1f22c1a8b4d049c33 and < 152983d87387f6a8ae72b73474cfa55fbcf1ec75
- affected>= 6acfe25968913788d30ec0eedd80178c4ea3f1d0 and < b5c037d6b807017e74a115288f81bc9cd5a5aab8
- affected>= d280c138e66be87d1fccfed42593f02fdb893905 and < a6d5ce2e1a2d7bf189bde8a659d04b65f0b0725d
- affected>= f32fea4c0234c971c12e46d76612cdc2dd4bb046 and < e24918ee67c4dc3d20d4670750e46e9b160365f4
- affected>= 46f781e0d151844589dc2125c8cce3300546f92a and < 37daa8c96bd563d03150e23f094cb60703594a6d
- affected>= 46f781e0d151844589dc2125c8cce3300546f92a and < 6493ebf9489efef0105078377b973ab33d51af22
- affected>= 46f781e0d151844589dc2125c8cce3300546f92a and < 8813b0612275cc61fe9e6603d0ee019247ade6be
- affected59bd04163e6451b9c7275277882ed9f4abfa2051
- affected>= 5.10.246 and < 5.10.261
- affected>= 5.15.196 and < 5.15.212
- affected>= 6.1.158 and < 6.1.178
- affected>= 6.6.114 and < 6.6.145
- affected>= 6.12.55 and < 6.12.97
- affected>= 6.17.5 and < 6.18
- affected6.18
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.