Linux kernel flaw in widely deployed krb5 crypto paths can lead to kernel memory corruption and compromise across servers and network services.
CVE-2026-64439
Linux kernel krb5 crypto use-after-free allowing kernel memory corruption.
Is CVE-2026-64439 being exploited?
Not confirmed. CVE-2026-64439 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.43% probability of exploitation in the next 30 days.
How severe is CVE-2026-64439?
CVE-2026-64439 is rated Critical with a CVSS score of 9.8. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-64439?
Yes. A fix has been recorded for CVE-2026-64439. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-64439 affect?
CVE-2026-64439 affects Linux kernel (krb5 crypto: rfc3961_simplified/rfc8009_aes2), net/rxrpc (rxgk), fs/afs (cm_security), net/ceph (crypto), and 1 further product or version. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-64439?
Apply vendor kernel security updates immediately; disable async AEAD modules if unable to patch.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Slab use-after-free in kernel crypto can cause crashes, escalate to kernel RCE or full system compromise via networked krb5 paths.
Immediate action required
- affected>= 00244da40f7821b242c4612428d4192230dba27f and < ef6feb77e2d91761427c5b773edc9c97e1b706ad
- affected>= 00244da40f7821b242c4612428d4192230dba27f and < 2b7bd6dccff14b8b632c5244f1fd506918077221
- affected>= 00244da40f7821b242c4612428d4192230dba27f and < 6c9dddeb582fde005360f4fe02c760d45ca05fb5
- affected6.15
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.