PT-2026-64797 · Linux+1 · Linux Kernel+1

CVE-2026-64530

·

Published

2026-06-23

·

Updated

2026-09-09

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the net/sched component where the tcf qevent handle() function fails to properly handle the TC ACT CONSUMED return value from tcf classify(). This occurs when a socket buffer (skb) is held by the defragmentation engine, such as during act ct operations on out-of-order fragments, meaning the caller no longer owns the skb. Because tcf qevent handle() does not account for this state, it returns the skb to the caller as if classification succeeded. Consequently, the red enqueue() function may continue to operate on the skb by enqueueing, dropping, or updating statistics, leading to a Use-After-Free (UAF) condition. A Use-After-Free is a memory corruption issue where an application continues to use a pointer after it has been freed.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

ALSA-2026:49211
ALSA-2026:49212
ALSA-2026:49213
ALSA-2026:49214
AZL-93957
CVE-2026-64530
OPENSUSE-SU-2026:11476-1
OPENSUSE-SU-2026:21555-1
RHSA-2026:47620
RHSA-2026:48222
RHSA-2026:49032
SUSE-SU-2026:23066-1
SUSE-SU-2026:23068-1
SUSE-SU-2026:23193-1
SUSE-SU-2026:23194-1
SUSE-SU-2026:23221-1
SUSE-SU-2026:23231-1
SUSE-SU-2026:23237-1
SUSE-SU-2026:23241-1
SUSE-SU-2026:23244-1
SUSE-SU-2026:23257-1
SUSE-SU-2026:23258-1
SUSE-SU-2026:23259-1
SUSE-SU-2026:23260-1
SUSE-SU-2026:23261-1
SUSE-SU-2026:23262-1
SUSE-SU-2026:23263-1
SUSE-SU-2026:23264-1
SUSE-SU-2026:23265-1
SUSE-SU-2026:23266-1
SUSE-SU-2026:23267-1
SUSE-SU-2026:23268-1
SUSE-SU-2026:23269-1
SUSE-SU-2026:23270-1
SUSE-SU-2026:23271-1
SUSE-SU-2026:23272-1
SUSE-SU-2026:23279-1
SUSE-SU-2026:23280-1
SUSE-SU-2026:23281-1
SUSE-SU-2026:23282-1
SUSE-SU-2026:23283-1
SUSE-SU-2026:23284-1
SUSE-SU-2026:23285-1
SUSE-SU-2026:23286-1
SUSE-SU-2026:23287-1
SUSE-SU-2026:23288-1
SUSE-SU-2026:23290-1
SUSE-SU-2026:23291-1
SUSE-SU-2026:23292-1
SUSE-SU-2026:23293-1
SUSE-SU-2026:23295-1
SUSE-SU-2026:23296-1
SUSE-SU-2026:23328-1
SUSE-SU-2026:23329-1
SUSE-SU-2026:23330-1
SUSE-SU-2026:23331-1
SUSE-SU-2026:23332-1
SUSE-SU-2026:23333-1
SUSE-SU-2026:23334-1
SUSE-SU-2026:23335-1
SUSE-SU-2026:23336-1
SUSE-SU-2026:23337-1
SUSE-SU-2026:23338-1
SUSE-SU-2026:23339-1
SUSE-SU-2026:23340-1
SUSE-SU-2026:23341-1
SUSE-SU-2026:23342-1
SUSE-SU-2026:23343-1
SUSE-SU-2026:23366-1
SUSE-SU-2026:23367-1
SUSE-SU-2026:23368-1
SUSE-SU-2026:23369-1
SUSE-SU-2026:23370-1
SUSE-SU-2026:23371-1
SUSE-SU-2026:23372-1
SUSE-SU-2026:23373-1
SUSE-SU-2026:23374-1
SUSE-SU-2026:23375-1
SUSE-SU-2026:23376-1
SUSE-SU-2026:23377-1
SUSE-SU-2026:23378-1
SUSE-SU-2026:23379-1
SUSE-SU-2026:23380-1
SUSE-SU-2026:23381-1
SUSE-SU-2026:23382-1
SUSE-SU-2026:23383-1
SUSE-SU-2026:23384-1
SUSE-SU-2026:23385-1
SUSE-SU-2026:23386-1
SUSE-SU-2026:23387-1
SUSE-SU-2026:23388-1
SUSE-SU-2026:23389-1
SUSE-SU-2026:23390-1
SUSE-SU-2026:3595-1
SUSE-SU-2026:3602-1
SUSE-SU-2026:3617-1
SUSE-SU-2026:3689-1
SUSE-SU-2026:3694-1
SUSE-SU-2026:3696-1
SUSE-SU-2026:3697-1
SUSE-SU-2026:3698-1
SUSE-SU-2026:3699-1
SUSE-SU-2026:3700-1
SUSE-SU-2026:3701-1
SUSE-SU-2026:3703-1
SUSE-SU-2026:3704-1
SUSE-SU-2026:3708-1
SUSE-SU-2026:3710-1
SUSE-SU-2026:3715-1
SUSE-SU-2026:3717-1
SUSE-SU-2026:3719-1
SUSE-SU-2026:3724-1
SUSE-SU-2026:3726-1
SUSE-SU-2026:3729-1
SUSE-SU-2026:3739-1
SUSE-SU-2026:3744-1
SUSE-SU-2026:3746-1
SUSE-SU-2026:3748-1
SUSE-SU-2026:3754-1
SUSE-SU-2026:3759-1
SUSE-SU-2026:3760-1
SUSE-SU-2026:3761-1
SUSE-SU-2026:3768-1
SUSE-SU-2026:3770-1
SUSE-SU-2026:3771-1
SUSE-SU-2026:3774-1
SUSE-SU-2026:3775-1
SUSE-SU-2026:3776-1
SUSE-SU-2026:3777-1
SUSE-SU-2026:3778-1
SUSE-SU-2026:3779-1
SUSE-SU-2026:3780-1
SUSE-SU-2026:3781-1
SUSE-SU-2026:3790-1
SUSE-SU-2026:3807-1
SUSE-SU-2026:3810-1
SUSE-SU-2026:3819-1
SUSE-SU-2026:3821-1
ZDI-26-571

Affected Products

Linux Kernel
Rocky Linux