Kernel-level remote UAF in the ubiquitous Linux networking stack can crash or enable RCE across many systems; high CVSS and broad impact justify wide distribution.
CVE-2026-64530
Linux kernel RED qdisc UAF via TC_ACT_CONSUMED on defragged fragments
Is CVE-2026-64530 being exploited?
Not confirmed. CVE-2026-64530 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.54% probability of exploitation in the next 30 days.
How severe is CVE-2026-64530?
CVE-2026-64530 is rated Critical with a CVSS score of 9.8. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-64530?
Yes. A fix has been recorded for CVE-2026-64530. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-64530 affect?
CVE-2026-64530 affects Linux kernel net/sched (qdisc RED), Systems using conntrack defrag (nf_conntrack), Linux distributions running affected kernels. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-64530?
Apply vendor/kernel security updates immediately; temporarily disable RED qevents or conntrack defrag if patching delayed
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Remote use-after-free in kernel networking path allowing kernel crash (DoS) or possible remote code execution/privilege escalation via crafted fragmented packets.
Immediate action required
- affected>= 172ba7d46c202e679f3ccb10264c67416aaeb1c4 and < 5ed3d6f85991656667059d3fa5a1d683ac58c447
- affected>= 0b5b831122fc3789fff75be433ba3e4dd7b779d4 and < f42e8134a3a1074b834a574d404352f867ba994a
- affected>= 73f7da5fd124f2cda9161e2e46114915e6e82e97 and < 447d493034a9cf7bf13a2abac86d0573d907ec2f
- affected>= 3f14b377d01d8357eba032b4cabc8c1149b458b6 and < e1270e69dcf2c3512c453484178f2e9dc0db3f05
- affected>= 3f14b377d01d8357eba032b4cabc8c1149b458b6 and < 2140c2f3f2e7b066e1ae616ede8856cafd8015e9
- affected>= 3f14b377d01d8357eba032b4cabc8c1149b458b6 and < e28aedab9488343924d227b5a896faed67ce84d5
- affected>= 3f14b377d01d8357eba032b4cabc8c1149b458b6 and < a8a02897f2b479127db261de05cbf0c28b98d159
- affectedf5346df0591d10bc948761ca854b1fae6d2ef441
- affected>= 5.15.148 and < 5.15.212
- affected>= 6.1.75 and < 6.1.178
- affected>= 6.6.14 and < 6.6.145
- affected>= 6.7.2 and < 6.8
- affected6.8
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.