In the Linux kernel, the following vulnerability has been resolved: test_kprobes: clear kprobes between test runs Running the kprobes sanity tests… (CVE-2026-64163)
A vulnerability in the Linux kernel's kprobes sanity tests causes kernel crashes when running the tests multiple times. The issue arises because kprobes retain leftover data between test runs, leading to registration failures and kernel paging faults. The problem was fixed by ensuring all kprobe data is cleared before each test run.
AI Analysis
Technical Summary
The Linux kernel vulnerability CVE-2026-64163 involves the kprobes testing framework where running the kprobes sanity tests twice causes all tests to fail and eventually crashes the kernel. This occurs because static kprobe variables retain leftover data after register and unregister operations, which is not fully cleared between test runs. Specifically, address and flags fields were not reset, causing subsequent register_kprobe calls to fail with error -22 and triggering kernel paging faults. The fix moves all kprobe cleanup operations into the kprobes_test_init function, which is called before each individual test, ensuring no residual data remains from previous runs.
Potential Impact
Repeated execution of the kprobes sanity tests can cause kernel crashes due to improper cleanup of kprobe data structures. This can lead to system instability and denial of service during testing. The vulnerability affects the kernel testing framework rather than production kernel operation, limiting its impact primarily to kernel developers or testers running these specific tests.
Mitigation Recommendations
A fix has been implemented that ensures all kprobe data is cleared before each test run by moving cleanup code into the kprobes_test_init function. Users should update to the patched Linux kernel version containing this fix. Since this is a kernel test framework issue, normal users are unlikely to be affected unless running these tests. Patch status is not explicitly stated; check the vendor or Linux kernel mailing lists for the official fixed version.
In the Linux kernel, the following vulnerability has been resolved: test_kprobes: clear kprobes between test runs Running the kprobes sanity tests… (CVE-2026-64163)
Description
A vulnerability in the Linux kernel's kprobes sanity tests causes kernel crashes when running the tests multiple times. The issue arises because kprobes retain leftover data between test runs, leading to registration failures and kernel paging faults. The problem was fixed by ensuring all kprobe data is cleared before each test run.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Linux kernel vulnerability CVE-2026-64163 involves the kprobes testing framework where running the kprobes sanity tests twice causes all tests to fail and eventually crashes the kernel. This occurs because static kprobe variables retain leftover data after register and unregister operations, which is not fully cleared between test runs. Specifically, address and flags fields were not reset, causing subsequent register_kprobe calls to fail with error -22 and triggering kernel paging faults. The fix moves all kprobe cleanup operations into the kprobes_test_init function, which is called before each individual test, ensuring no residual data remains from previous runs.
Potential Impact
Repeated execution of the kprobes sanity tests can cause kernel crashes due to improper cleanup of kprobe data structures. This can lead to system instability and denial of service during testing. The vulnerability affects the kernel testing framework rather than production kernel operation, limiting its impact primarily to kernel developers or testers running these specific tests.
Mitigation Recommendations
A fix has been implemented that ensures all kprobe data is cleared before each test run by moving cleanup code into the kprobes_test_init function. Users should update to the patched Linux kernel version containing this fix. Since this is a kernel test framework issue, normal users are unlikely to be affected unless running these tests. Patch status is not explicitly stated; check the vendor or Linux kernel mailing lists for the official fixed version.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-9292-g249-69fp
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-64163"]
- Ecosystems
- []
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a5d27a82a4a8d598912a54f
Added to database: 07/19/2026, 19:38:16 UTC
Last enriched: 07/19/2026, 19:41:14 UTC
Last updated: 07/20/2026, 17:26:47 UTC
Views: 11
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.