PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-64544 Linux CVE debrief

A vulnerability in the Linux kernel's crypto: asymmetric_keys - fix OOB read in pefile_digest_pe_contents has been resolved. The vulnerability occurs when the addition of hashed_bytes and certs_size exceeds pelen, causing an unsigned subtraction to underflow. This underflow is then passed to crypto_shash_update(), which reads out of bounds and panics on unmapped vmalloc guard pages.

Vendor
Linux
Product
Unknown
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-27
Original CVE updated
2026-08-17
Advisory published
2026-07-27
Advisory updated
2026-08-17

Who should care

Linux kernel maintainers and users, as the vulnerability can cause a kernel panic. They should review and apply patches, monitor updates, and inventory kernel versions to address potential exposure. Additionally, they should consider compensating controls for exposed systems and track exceptions during remediation efforts. This vulnerability affects Linux kernel deployments, and operators, platform administrators, vulnerability management teams, and security teams should be aware of its impact and take necessary actions to mitigate it. Those responsible for maintaining and securing Linux kernel-based systems should prioritize patching and verifying the integrity of their deployments to prevent potential exploitation. Users of Linux kernel should also be informed about the vulnerability and the steps being taken to address it. The vulnerability management process should include assessing the risk, applying patches, and verifying the effectiveness of the remediation. Furthermore, Linux kernel users should ensure that their systems are up-to-date and that any necessary mitigations are in place to prevent exploitation. Those affected should also consider reviewing monitoring, detection, and logs for exposed assets that need extra review. Overall, a coordinated effort is required to address this vulnerability and prevent potential exploitation. Linux kernel maintainers and users must work together to ensure that the necessary patches and mitigations are applied, and that the vulnerability is properly managed and remediated. By taking these steps, they can help prevent potential exploitation and ensure the security and integrity of their Linux kernel-based systems. The vulnerability can be addressed by reviewing and applying patches, monitoring Linux kernel updates, and inventorying kernel versions for potential exposure. Those responsible for Linux kernel deployments should prioritize patching and verifying the integrity of their deployments to prevent potential exploitation. The vulnerability affects Linux kernel deployments, and those responsible for maintaining and securing these systems should take necessary actions to mitigate it. Linux kernel users should be (

Technical summary

The vulnerability occurs in the pefile_digest_pe_contents function, where the addition of hashed_bytes and certs_size can exceed pelen, causing an unsigned subtraction to underflow. This underflow is then passed to crypto_shash_update(), which reads out of bounds and panics on unmapped vmalloc guard pages. The issue arises from a crafted PE file that can trigger this underflow, leading to a kernel panic. Linux kernel maintainers and users should be aware of this vulnerability and take necessary precautions.

Defensive priority

High priority for Linux kernel maintainers and users, as the vulnerability can cause a kernel panic.

Recommended defensive actions

  • Review and apply the patch to fix the OOB read in pefile_digest_pe_contents
  • Monitor Linux kernel updates for potential fixes
  • Inventory Linux kernel versions for potential exposure
  • Perform a thorough review of Linux kernel deployments to identify potential exposure
  • Inventory Linux kernel versions to determine which systems require patching or mitigation
  • Apply patches or mitigations to affected Linux kernel deployments
  • Monitor Linux kernel updates for potential fixes and apply them as necessary

Evidence notes

The vulnerability was introduced in the Linux kernel and can be triggered by a crafted PE file. The addition of hashed_bytes and certs_size can exceed pelen, causing an unsigned subtraction to underflow.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-64544 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-64544

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-64544 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-64544

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/627938383761fb4334b41ebe7ef438d6b8b19d60

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/6acd2fbd00f9c72aebefce63fc2e73e8f3d79061

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/7016377699b5b25b7ec3c0bf2ec3f983c7e95f7c

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/803591785d33cf13b6f73ce2796e8b9e6d5e6526

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/89efd998470a93284b7ad5a20d4e0e3c6858ae8e

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/b798ada5a5d1cb4cc4cfa72074b1b463eca6c506

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/e162bc386e71b5412425a38ee048e8d2185491b9

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.