PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-64560 Linux CVE debrief

A use-after-free vulnerability was found in the Linux kernel's posix-cpu-timers functionality. This issue is related to a non-leader exec() race that can result in a use-after-free (UAF) vulnerability. The vulnerability arises from a race condition in the posix_cpu_timer_del() and sys_timer_delete() functions in the Linux kernel. This can result in a use-after-free (UAF) vulnerability, allowing an attacker to potentially execute arbitrary code. The issue is related to the handling of posix CPU timers during the execution of a non-leader process. The vulnerability was reported by Wongi and Jungwoo, who decoded a non-leader exec() related race which can result in an UAF.

Vendor
Linux
Product
Unknown
CVSS
HIGH 7.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-29
Original CVE updated
2026-09-08
Advisory published
2026-07-29
Advisory updated
2026-09-08

Who should care

Linux kernel developers, Linux distribution maintainers, and users of Linux-based systems should be aware of this vulnerability and take steps to mitigate it. Linux kernel developers and maintainers should review the supplied patches and apply them to their systems. Users of Linux-based systems should ensure that their systems are updated with the latest kernel patches. Security teams should review the vulnerability and assess the potential impact on their systems. Vulnerability management teams should prioritize the patching of affected systems. Operators of Linux-based systems should be aware of the potential risks and take steps to mitigate them. Platform administrators should ensure that their systems are updated with the latest kernel patches. Security teams should review the vulnerability and assess the potential impact on their systems. Compliance teams should ensure that their systems are compliant with the latest kernel patches. Asset owners should be aware of the potential risks and take steps to mitigate them. Incident response teams should be prepared to respond to potential attacks. Penetration testers and red teamers should be aware of the vulnerability and test for it in their assessments. Blue teamers and defenders should be aware of the vulnerability and take steps to detect and prevent potential attacks. Auditors and compliance teams should review the vulnerability and assess the potential impact on their systems. Threat hunters should be aware of the vulnerability and take steps to detect potential attacks. Security architects should review the vulnerability and assess the potential impact on their systems. Security engineers should review the vulnerability and take steps to mitigate it. Security researchers should be aware of the vulnerability and take steps to study and mitigate it. System administrators should ensure that their systems are updated with the latest kernel patches. Network administrators should be aware of the potential risks and take steps to mitigate them. Cloud administrators should ensure that their systems are updated with the latest kernel patches. DevOps teams should review the vulnerability and take steps to mitigate它.

Technical summary

The vulnerability arises from a race condition in the posix_cpu_timer_del() and sys_timer_delete() functions in the Linux kernel. This can result in a use-after-free (UAF) vulnerability, allowing an attacker to potentially execute arbitrary code. The issue is related to the handling of posix CPU timers during the execution of a non-leader process. The vulnerability was reported by Wongi and Jungwoo, who decoded a non-leader exec() related race which can result in an UAF. The issue arises from a race condition in the posix_cpu_timer_del() and sys_timer_delete() functions. The vulnerability can be triggered by a non-leader exec() race, which can result in a use-after-free (UAF) vulnerability.

Defensive priority

High

Recommended defensive actions

  • Apply the kernel patches provided to address the vulnerability
  • Restrict access to sensitive systems and data
  • Monitor system logs for suspicious activity
  • Implement compensating controls to mitigate potential attacks
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The vulnerability was reported by Wongi and Jungwoo, who decoded a non-leader exec() related race which can result in an UAF. The issue arises from a race condition in the posix_cpu_timer_del() and sys_timer_delete() functions.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-64560 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-64560

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-64560 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-64560

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/12a891c773aeb5823d63dbd0cb2ab931d6c21c9b

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/67aa823e3e8c229c6d374df79c804f6721cb83b6

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/6a7ecc25abe6f0fecc6e62a05096987200edbd02

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/920f893f735e92ba3a1cd9256899a186b161928d

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/ad1cafa1bdaa71da85d71cac053838bbe97852b6

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/cc35ddbc497311e0b6b9a6a6a4f4d1217d6ab1aa

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/d8bcb28abad857f1415da7656f19b2ada90af04f

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.