PatchSiren cyber security CVE debrief
CVE-2026-64005 Linux CVE debrief
A vulnerability in the Linux kernel has been resolved. The vulnerability is related to the re-initialization of smc hashtables, which can lead to a corrupted list. The re-initialization is unnecessary and can be removed. The affected product is the Linux kernel. The vulnerability has been resolved by removing the unnecessary re-initialization of smc hashtables.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-19
- Original CVE updated
- 2026-07-30
- Advisory published
- 2026-07-19
- Advisory updated
- 2026-07-30
Who should care
Users of the Linux kernel should be aware of this vulnerability and take necessary precautions. The vulnerability has been resolved, and users should apply the patches or updates provided by the vendor.
Technical summary
The vulnerability is caused by the re-initialization of smc hashtables after smc_nl_init(), proto_register() and sock_register(). This can lead to smc_v*_hashinfo.ht being reset even though hash entries already exist and are being used, possibly resulting in a corrupted list. The vulnerability has been resolved by removing the unnecessary re-initialization of smc hashtables. The affected product is the Linux kernel. Users of the Linux kernel should be aware of this vulnerability and take necessary precautions. The re-initialization is unnecessary and can be removed, and the vulnerability has been resolved by this change. Additional verification and defensive measures are recommended to ensure the security of the system.
Defensive priority
Medium
Recommended defensive actions
- Inventory and assess Linux kernel usage
- Apply vendor patches or updates
- Monitor for suspicious activity
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record was published on 2026-07-19T16:17:40.170Z and has not been modified since then. The NVD entry is currently Received. The vulnerability is related to the re-initialization of smc hashtables in the Linux kernel, which can lead to a corrupted list. The re-initialization is unnecessary and can be removed. The affected product is the Linux kernel. The vulnerability has been resolved.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-64005 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-64005
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-64005 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-64005
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/0cc9d0ac22d02f1ba1884de5d6de9eaf8b45d82d
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/2006605006e5a4a11d93e1ebdbbe95764d24276f
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/55cba6b883b41e5922c00ba9d4e3262131f46f1b
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/5ec939367e700722ffbb1b7cacccbb1a3cf0ebd1
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/64c96e497d5ada0b90e99bf58f893aa2b73dcfbc
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/9e4389b0038781f19f97895186ed941ff8ac1678
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/cdc79c05cc375f68ae87b0c74fdaac1a5c93155a
416baaa9-dc9f-4396-8d5f-8c081fb06d67
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.