CVE-2026-64450
A flaw in the Linux kernel’s TIPC implementation allows an attacker to trigger an out‑of‑bounds read when processing certain broadcast messages. The vulnerability could lead to kernel memory corruption and potentially privilege escalation. It has been fixed in recent kernel releases.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Linux kernel systems that use the TIPC protocol, typically servers and services that rely on inter‑process communication over TIPC.
Real-world impact
An attacker could send a crafted broadcast message that causes the kernel to read beyond the bounds of a packet, potentially corrupting memory, crashing the system, or escalating privileges.
Why this severity
The CVSS score of 9.1 reflects the high impact of a remote attacker being able to read arbitrary kernel memory and potentially gain elevated privileges, with no authentication or user interaction required.
What to do about it
- 011. Check your current kernel version.
- 022. Update to a kernel version that includes the CVE‑2026‑64450 fix (e.g., by installing the latest kernel package from your distribution).
- 033. Reboot into the updated kernel.
NVD-referenced vendor advisory
Timeline
- Jul 25, 2026 · 7d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 27, 2026 · 5d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- git.kernel.org/stable/c/016f5995c37a5a2c45…
- git.kernel.org/stable/c/055663d21dc4336f67…
- git.kernel.org/stable/c/2b66974a1b6134a4bb…
- git.kernel.org/stable/c/2de42e268174766cb2…
- git.kernel.org/stable/c/74b45af86a767594ba…
- git.kernel.org/stable/c/9a51115fcdc78687c8…
- git.kernel.org/stable/c/a21ed5064217cc3372…
- git.kernel.org/stable/c/f333b6851bdf326fd2…