Core Linux kernel flaw affecting widely deployed OS kernels; can enable kernel compromise or widespread outages, impacting most Linux-hosted infrastructure.
CVE-2026-64523
Linux kernel use-after-free race in net/handshake can compromise or crash systems.
Is CVE-2026-64523 being exploited?
Not confirmed. CVE-2026-64523 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.36% probability of exploitation in the next 30 days.
How severe is CVE-2026-64523?
CVE-2026-64523 is rated Critical with a CVSS score of 9.8. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-64523?
Yes. A fix has been recorded for CVE-2026-64523. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-64523 affect?
CVE-2026-64523 affects Linux kernel (net/handshake subsystem), Distribution kernels (all vendors using affected code). Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-64523?
Apply vendor kernel patches and reboot affected hosts immediately
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Local attacker can trigger a kernel use-after-free leading to denial-of-service or potential privilege escalation/arbitrary kernel code execution.
Immediate action required
- affected>= 3b3009ea8abb713b022d94fba95ec270cf6e7eae and < 685b10dd0e32c7782cead16c8cf055c609678583
- affected>= 3b3009ea8abb713b022d94fba95ec270cf6e7eae and < b913801ad9b9a51437d84d030ec6843e08976bd6
- affected>= 3b3009ea8abb713b022d94fba95ec270cf6e7eae and < 16eaba5aa89c04eea125905bb8f988c1897f4f29
- affected>= 3b3009ea8abb713b022d94fba95ec270cf6e7eae and < 09dba37eee70d0596e26645015f1aa95a9848e9d
- affected6.4
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.