CVE-2026-64490
Linux kernel virtio-snd trusts device metadata, enabling OOB kernel access.
Is CVE-2026-64490 being exploited?
Not confirmed. CVE-2026-64490 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.15% probability of exploitation in the next 30 days.
How severe is CVE-2026-64490?
CVE-2026-64490 is rated High with a CVSS score of 8.4. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-64490?
Yes. A fix has been recorded for CVE-2026-64490. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-64490 affect?
CVE-2026-64490 affects Linux kernel (virtio-snd), QEMU/KVM guests using virtio-audio, Distributions shipping affected kernels. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-64490?
Install kernel updates; disable virtio-snd or block untrusted virtio devices if needed.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
A malicious or buggy virtio audio device can trigger out-of-bounds kernel access, causing crashes, memory corruption and possible privilege escalation.
Patch when possible
- affected>= d6568e3de42dd971a1356f7ba581e6600d53f0a0 and < 3243563f99ef5d3949b934bd6390a5679405d0e1
- affected>= d6568e3de42dd971a1356f7ba581e6600d53f0a0 and < 5da9742de22db0dbaa8d414214ab5e1bedde00f9
- affected>= d6568e3de42dd971a1356f7ba581e6600d53f0a0 and < 21584672fd699abe1768241d6c501b2de6139b6a
- affected>= d6568e3de42dd971a1356f7ba581e6600d53f0a0 and < c77a6cbb36ff8cbc1f084d94f8dcda5250935271
- affected6.9
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.