CVE-2026-64434
Linux kernel Bluetooth L2CAP UAF enabling kernel crash and possible privilege escalation.
Is CVE-2026-64434 being exploited?
Not confirmed. CVE-2026-64434 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.26% probability of exploitation in the next 30 days.
How severe is CVE-2026-64434?
CVE-2026-64434 is rated High with a CVSS score of 8.8. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-64434?
Yes. A fix has been recorded for CVE-2026-64434. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-64434 affect?
CVE-2026-64434 affects Linux kernel - Bluetooth L2CAP (net/bluetooth/l2cap_core). Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-64434?
Apply kernel update with fix ASAP; restrict/disable Bluetooth until patched.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Bluetooth-triggered kernel use-after-free: remote-in-range attacker can crash the kernel (DoS) and may achieve kernel code execution/privilege escalation.
Patch when possible
- affected>= 3634cbdc2eb414b69ffa752ddbe5e0458518e321 and < 8f90405a4a6f1f1880dc07996b47bf57c712bd8a
- affected>= e1c100e2d61bd8c718b7d91fe3e050780a9bf72d and < 32d783cafb46ff3ca58e6f9fd62c9c5f35eaf26b
- affected>= deb8493a8fa599f6c95e2465b12bfdfb7f94a1d9 and < 8922c7940bae9ce4b1736dddb6362370793835c2
- affected>= 89dec92041717b027216e110599e4f6d6c921b79 and < 91047a4396a8b1857a6f712a90cf33ec0012b189
- affected>= 50dfec218808b148ab4247b1858031b7a32015c5 and < 0b0e2bf39cf99e458d991b9df253727e036a7d7d
- affected>= 859d3ace791ed878ae9ba5522c7844d960da8f88 and < d3b739db5dc6f688a60d56da872fabaf65246032
- affected>= 8c8e620467a7b51562dbcefbd1f09f288d7d710d and < 50c38d9f42a529691e4e67ea9cedf4f0bfc8d277
- affected>= 8c8e620467a7b51562dbcefbd1f09f288d7d710d and < b66774b48dd98f07254951f74ea6f513efe7ff8b
- affected7555fd885a0603f50e49a655850a1f2bd8a25398
- affected>= 5.10.259 and < 5.10.265
- affected>= 5.15.210 and < 5.15.216
- affected>= 6.1.176 and < 6.1.183
- affected>= 6.6.143 and < 6.6.145
- affected>= 6.12.93 and < 6.12.97
- affected>= 6.18.35 and < 6.18.39
- affected>= 7.0.12 and < 7.1
- affected7.1
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.