PT-2026-64698 · Linux+1 · Linux Kernel+1

CVE-2026-64477

·

Published

2026-07-25

·

Updated

2026-09-07

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An out-of-bounds access occurs in the x86 architecture when offlining a CPU on systems with Sub-NUMA Clustering (SNC) enabled. The issue arises when a monitoring domain is being taken offline and its cpu mask becomes empty. In this state, the system attempts to determine the NUMA node ID by calling the cpu to node() function using nr cpu ids as an argument, which leads to the out-of-bounds access. This happens because the limbo handler attempts to read the current event value of a busy Resource Monitoring ID (RMID) to convert a logical RMID to a physical RMID, but cannot find a valid CPU associated with the domain.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-64477
OPENSUSE-SU-2026:11476-1
USN-8726-1
USN-8727-1
USN-8728-1

Affected Products

Linux Kernel
Ubuntu