CVE-2026-64435
Linux kernel audit subsystem data race can cause kernel crash or corruption.
Is CVE-2026-64435 being exploited?
Not confirmed. CVE-2026-64435 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.33% probability of exploitation in the next 30 days.
How severe is CVE-2026-64435?
CVE-2026-64435 is rated High with a CVSS score of 8.2. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-64435?
Yes. A fix has been recorded for CVE-2026-64435. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-64435 affect?
CVE-2026-64435 affects Linux kernel (audit subsystem / kauditd/auditd), Linux distributions with vulnerable kernels, Servers and endpoints running auditd. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-64435?
Install vendor kernel security update and restart auditd/kauditd.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Local processes can trigger a kernel data-race causing crashes (DoS) or memory corruption, possibly enabling local privilege escalation.
Patch when possible
- affected>= 3197542482df22c2a131d4a813280bd7c54cedf5 and < 69f98fff30bdaa72b0cb0e7e078ab6456a0a59b0
- affected>= 3197542482df22c2a131d4a813280bd7c54cedf5 and < b35597bdae1a5d8395da4b9baa993b9b71f74d68
- affected>= 3197542482df22c2a131d4a813280bd7c54cedf5 and < e575dabb805252e3113fdc3f56f6ecacfde422d0
- affected>= 3197542482df22c2a131d4a813280bd7c54cedf5 and < 7ff42312ccde549f8c698723822c7db35107a39b
- affected>= 3197542482df22c2a131d4a813280bd7c54cedf5 and < a3d85dec60bb0622360fc176b2a51abdbe2ff0ad
- affected>= 3197542482df22c2a131d4a813280bd7c54cedf5 and < fe997a84a385f840b593ead92e575503a5046cee
- affected>= 3197542482df22c2a131d4a813280bd7c54cedf5 and < c5186201fa7030289cc4fe23fae87a3fcb566856
- affected>= 3197542482df22c2a131d4a813280bd7c54cedf5 and < c9a71daaecb2fb1d8c704545cc0b1c920b9bf5d7
- affected4.10
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.