Critical· 9.8official fix available
CVE-2026-64439
CVE-2026-64439 is a critical Linux kernel vulnerability where async AEAD implementations in krb5 could cause use-after-free memory errors, leading to potential system crashes or data corruption. The fix involves filtering out async AEAD instances during allocation.
publishedJul 25, 2026
last modifiedJul 27, 2026
sourcesNVD
severity · cvss
9.8
critical · how bad it is
exploitation · epss
<1%
35th percentile · chance of exploitation in 30 days
(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
auto-deletes from the system
counting…on Aug 26, 2026
An official fix is available, so this entry is kept for 30 days and then removed automatically.
01
Who is affected
Systems using Linux kernel with async AEAD providers bound to krb5 enctype (e.g., rxrpc, AFS, Ceph components)
02
Real-world impact
Could allow attackers to cause kernel crashes or memory corruption via network services or file systems using krb5 encryption.
03
Why this severity
CVSS 9.8 (critical): High confidence in exploitability and severe impact on system stability/availability.
04
What to do about it
official fix available
recommended steps
- 011. Upgrade Linux kernel to a version containing the patch for CVE-2026-64439.
- 022. Apply kernel security updates from your distribution's repository.
- 033. Restart affected services (e.g., rxrpc, AFS, Ceph) after kernel update.
NVD description detailing kernel fix
05
Timeline
- Jul 25, 2026 · 7d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 27, 2026 · 5d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
06
How it’s attacked
Attack vectorNetwork (remote)
Attack complexityLow
Privileges requiredNone
User interactionNone needed
ScopeUnchanged
Confidentiality impactHigh
Integrity impactHigh
Availability impactHigh
07
(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →