CVE-2026-64122
A critical use‑after‑free bug in the Linux kernel’s mlx5e driver can let an attacker crash the kernel or potentially run code. The flaw occurs when a network channel is torn down while a timeout handler still accesses its data. The kernel team has patched the code to use a safe reference, eliminating the vulnerability.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Linux kernel, specifically the mlx5e driver for Mellanox (MLX5) network devices. Users running affected kernel versions on systems with Mellanox NICs are at risk.
Real-world impact
An attacker could crash the kernel, causing a denial of service, or potentially execute arbitrary code with kernel privileges, leading to full system compromise.
Why this severity
The CVSS score of 9.8 reflects that the flaw can be exploited remotely with no authentication or user interaction, and it allows complete compromise of confidentiality, integrity, and availability.
What to do about it
- 01Upgrade the Linux kernel to a version that includes the patch for CVE-2026-64122.
- 02Restart the system to load the updated kernel.
NVD description indicates official fix
Timeline
- Jul 19, 2026 · 14d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 20, 2026 · 13d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
- Jul 30, 2026 · 3d agoAdvisory updatedThe NVD record was last revised.