Threats Tagged 'cve-2026-64530'
View all threats tagged with 'cve-2026-64530'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-64530'
Click on any threat for detailed analysis and mitigation recommendations
The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: ksm: use range-walk function to jump over holes in scan_get_next_rmap_item (CVE-2025-68211) * kernel: ip6_tunnel: use skb_vlan_inet_prepare() in __ip6_tnl_rcv() (CVE-2026-23003) * kernel: netfilter: nft_set_pipapo_avx2: don't return non-matching entry on expiry (CVE-2026-43114) * kernel: sctp: purge outqueue on stale COOKIE-ECHO handling (CVE-2026-52924) * kernel: netfilter: xt_policy: fix strict mode inbound policy matching (CVE-2026-52920) * kernel: zram: fix use-after-free in zram_bvec_write_partial() (CVE-2026-53185) * kernel: netfilter: require Ethernet MAC header before using eth_hdr() (CVE-2026-53131) * kernel: netfilter: conntrack_irc: fix possible out-of-bounds read (CVE-2026-53268) * kernel: i2c: stub: Reject I2C block transfers with invalid length (CVE-2026-64191) * kernel: netfilter: ipset: fix race between dump and ip_set_list resize (CVE-2026-64189) * kernel: Input: synaptics-rmi4 - bound the F3A keymap to the GPIO count (CVE-2026-64277) * kernel: Input: synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count (CVE-2026-64276) * kernel: net: ipv6: use-after-free in fib6_rule_suppress due to stale res->rt6 pointer (CVE-2026-74581) Bug Fix(es) and Enhancement(s): * [RHEL-9.8.z] Intel CWF: CPU is unable to obtain cstate1 on idle system (JIRA:RHEL-166118) * ss core dumped when there is an SCTP session [rhel-9.8.z] (JIRA:RHEL-212398) * [IBM 9.9 FEAT] zcrypt driver overwrite function - kernel part [rhel-9.8.z] (JIRA:RHEL-245333) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 08/26/2026, 06:06:27 UTC Added: 07/18/2026, 11:33:50 UTC |
This is a kernel live patch module which can be loaded by the kpatch command line utility to modify the code of a running kernel. This patch module is targeted for kernel-4.18.0-553.53.1.el8_10. Security Fix(es): * kernel: ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach() (CVE-2026-43038) * kernel: dlm: validate length in dlm_search_rsb_tree (CVE-2026-43125) * kernel: netfilter: flowtable: strictly check for maximum number of actions (CVE-2026-43329) * kernel: net: sched: UAF via missing handler for TC_ACT_CONSUMED in tcf_qevent_handle (CVE-2026-64530) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 08/17/2026, 16:04:51 UTC Added: 07/16/2026, 10:38:58 UTC |
This is a kernel live patch module which can be loaded by the kpatch command line utility to modify the code of a running kernel. This patch module is targeted for kernel-6.12.0-211.16.1.el10_2. Security Fix(es): * kernel: rxrpc: Fix RxGK token loading to check bounds (CVE-2026-31641) * kernel: ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach() (CVE-2026-43038) * kernel: netfilter: flowtable: strictly check for maximum number of actions (CVE-2026-43329) * kernel: netfilter: nft_inner: Fix IPv6 inner_thoff desync (CVE-2026-46244) * kernel: net: sched: UAF via missing handler for TC_ACT_CONSUMED in tcf_qevent_handle (CVE-2026-64530) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 08/17/2026, 14:25:46 UTC Added: 07/31/2026, 15:38:36 UTC |
0 The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: ipc: limit next_id allocation to the valid ID range (CVE-2026-52923) * kernel: tipc: fix double-free in tipc_buf_append() (CVE-2026-52993) * kernel: net: sched: UAF via missing handler for TC_ACT_CONSUMED in tcf_qevent_handle () * kernel: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle (CVE-2026-64530) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 07/31/2026, 22:14:03 UTC Added: 07/30/2026, 05:47:05 UTC |
0 The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements. Security Fix(es): * kernel: rtnetlink: add missing netlink_ns_capable() check for peer netns (CVE-2026-31692) * kernel: netfilter: ctnetlink: ensure safe access to master conntrack (CVE-2026-43116) * kernel: fanotify: fix false positive on permission events (CVE-2026-46150) * kernel: net: sched: UAF via missing handler for TC_ACT_CONSUMED in tcf_qevent_handle () * kernel: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle (CVE-2026-64530) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 07/31/2026, 18:16:27 UTC Added: 07/18/2026, 11:21:29 UTC |
In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle tcf_classify() can return TC_ACT_CONSUMED while the skb is held by the defragmentation engine (e.g. act_ct on out-of-order fragments). When that happens the skb is no longer owned by the caller and must not be touched again. tcf_qevent_handle() did not handle TC_ACT_CONSUMED: it fell through the switch and returned the skb to the caller as if classification had passed. The only qdisc that wires up qevents today is RED, via three call sites (qe_mark on RED_PROB_MARK/HARD_MARK, qe_early_drop on congestion_drop) red_enqueue() was continuing to operate on an skb it no longer owns in this case -- enqueueing it, dropping it, or updating statistics. Resulting in a UAF. tc qdisc add dev eth0 root handle 1: red ... qevent early_drop block 10 tc filter add block 10 ... action ct (with ct defrag enabled and traffic that produces out-of-order fragments, e.g. a fragmented UDP stream) Handle TC_ACT_CONSUMED in tcf_qevent_handle() the same way the ingress and egress fast paths do: treat it as stolen and return NULL without touching the skb. Unlike the TC_ACT_STOLEN case, the skb must not be dropped/freed here, as it is no longer owned by us. Join the discussion | GCVE Database | 07/26/2026, 07:16:00 UTC Added: 07/26/2026, 22:47:45 UTC |
In the Linux kernel, the following vulnerability has been resolved: ipc: limit next_id allocation to the valid ID range The checkpoint/restore sysctl path can request the next SysV IPC id through ids->next_id. ipc_idr_alloc() currently forwards that request to idr_alloc() with an open-ended upper bound. If the valid tail of the SysV IPC id space is full, the allocation can spill beyond ipc_mni. The returned SysV IPC id still uses the normal index encoding, so later lookup and removal can target the wrong slot. This leaves the real IDR entry behind and breaks the IDR state for the object. The bug is in ipc_idr_alloc() in the checkpoint/restore path. 1. ids->next_id is passed to: idr_alloc(&ids->ipcs_idr, new, ipcid_to_idx(next_id), 0, ...) 2. The zero upper bound makes the allocation effectively open-ended. Once the valid SysV IPC tail is occupied, idr_alloc() can spill past ipc_mni and allocate an entry beyond the valid IPC id range. 3. The new object id is still encoded with the narrower SysV IPC index width: new->id = (new->seq << ipcmni_seq_shift()) + idx 4. Later removal goes through ipc_rmid(), which uses: ipcid_to_idx(ipcp->id) That truncates the real IDR index. An object actually stored at a high index can then be removed as if it lived at a low in-range index. 5. For shared memory, shm_destroy() frees the current object anyway, but the real high IDR slot is left behind as a dangling pointer. 6. A subsequent walk of /proc/sysvipc/shm reaches the stale IDR entry and dereferences freed memory. Prevent this by bounding the requested allocation to ipc_mni so the checkpoint/restore path fails once the valid range is exhausted. Join the discussion | GCVE Database | 06/24/2026, 08:16:00 UTC Added: 07/17/2026, 10:18:33 UTC |
Showing 1 to 7 of 7 results