Vulnary
← back to the feed
Critical· 9.1official fix available

CVE-2026-64450

A flaw in the Linux kernel’s TIPC implementation allows an attacker to trigger an out‑of‑bounds read when processing certain broadcast messages. The vulnerability could lead to kernel memory corruption and potentially privilege escalation. It has been fixed in recent kernel releases.

publishedJul 25, 2026
last modifiedJul 27, 2026
sourcesNVD
severity · cvss
9.1
critical · how bad it is
exploitation · epss
<1%
42th percentile · chance of exploitation in 30 days
(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
auto-deletes from the system
counting…on Aug 26, 2026

An official fix is available, so this entry is kept for 30 days and then removed automatically.

01

Who is affected

Linux kernel systems that use the TIPC protocol, typically servers and services that rely on inter‑process communication over TIPC.

02

Real-world impact

An attacker could send a crafted broadcast message that causes the kernel to read beyond the bounds of a packet, potentially corrupting memory, crashing the system, or escalating privileges.

03

Why this severity

The CVSS score of 9.1 reflects the high impact of a remote attacker being able to read arbitrary kernel memory and potentially gain elevated privileges, with no authentication or user interaction required.

04

What to do about it

official fix available
recommended steps
  1. 011. Check your current kernel version.
  2. 022. Update to a kernel version that includes the CVE‑2026‑64450 fix (e.g., by installing the latest kernel package from your distribution).
  3. 033. Reboot into the updated kernel.

NVD-referenced vendor advisory

05

Timeline

  1. Jul 25, 2026 · 7d ago
    Published
    Disclosed and added to the National Vulnerability Database.
  2. Jul 27, 2026 · 5d ago
    Official fix available
    A vendor patch or mitigation now exists — see the remediation steps above.
06

How it’s attacked

Attack vectorNetwork (remote)
Attack complexityLow
Privileges requiredNone
User interactionNone needed
ScopeUnchanged
Confidentiality impactHigh
Integrity impactNone
Availability impactHigh
07

References & advisories

(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →