CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2026-64004: linux kernel from 3.4 (inclusive), before 5.10.259 (exclusive), from 5.11 (inclusive), before 5.15.210 (exclusive)…

CVE-2026-64004. CVSS 3.1 base score 7.8 (HIGH, Source advisory). EPSS 0.00129 (percentile 0.02207), scored 2026-10-08.

Affected technology

linux kernel · from 3.4 (inclusive), before 5.10.259 (exclusive)
linux

linux kernel · from 5.11 (inclusive), before 5.15.210 (exclusive)
linux

linux kernel · from 5.16 (inclusive), before 6.1.176 (exclusive)
linux

linux kernel · from 6.2 (inclusive), before 6.6.143 (exclusive)
linux

linux kernel · from 6.7 (inclusive), before 6.12.93 (exclusive)
linux

linux kernel · from 6.13 (inclusive), before 6.18.35 (exclusive)
linux

linux kernel · from 6.19 (inclusive), before 7.0.12 (exclusive)
linux

linux kernel · 7.1 · update rc1
linux

linux kernel · 7.1 · update rc2
linux

linux kernel · 7.1 · update rc3
linux

linux kernel · 7.1 · update rc4
linux

linux kernel · 7.1 · update rc5
linux

Linux · 51363b8751a673a00ad48eea895266396d53fa52 to before 884eb247b74d86db97e3a37f0d6fc8e1e83590dd, 51363b8751a673a00ad48eea895266396d53fa52 to before 45bb8de8c95d8899f4b8f61bd9bceb8132af73cb, 51363b8751a673a00ad48eea895266396d53fa52 to before 1fc30bd4e55e2dd622d2d366cecd732c1841bbee, 51363b8751a673a00ad48eea895266396d53fa52 to before cd691beafea0dd779e69e81ccc26b0ab50efcb5e, 51363b8751a673a00ad48eea895266396d53fa52 to before 6e792b8dd3002bbc4136745928a9605df1a72b8a, 51363b8751a673a00ad48eea895266396d53fa52 to before 9817369243380e287ebe5525411557eaa3aa2a79, 51363b8751a673a00ad48eea895266396d53fa52 to before 69554adc7a6fa04ede3ad7512321d83748e3c920, 51363b8751a673a00ad48eea895266396d53fa52 to before 3589d20a666caf30ad100c960a2de7de390fce88
Linux

Linux · 3.4
Linux

Component: Not specified by the source
File: net/iucv/af_iucv.c

Attack conditions (Source advisory, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

Any AF_IUCV HIPER user can potentially crash the kernel by racing recvmsg() with getsockopt(SO_MSGSIZE): the SO_MSGSIZE arm dereferences iucv->hs_dev->mtu after iucv_sock_close() (called from the racing recvmsg()) has set hs_dev to NULL, producing a NULL pointer dereference oops. Source advisory’s CVSS 3.1 assessment (base score 7.8/10) rates confidentiality, integrity and availability impact as high.

Published

CWE
CWE-667
CCR priority
31.2 /100 (P4)
CVSS 3.1
7.8 /10 · CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H · Source advisory
EPSS
0.00129 · percentile 0.02207 · 2026-10-08
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-64004.html