CVE-2026-64434 Vulnerability Analysis & Exploit Details

CVE-2026-64434
Vulnerability Scoring

8.8
/10
Severe Risk

Cybersecurity professionals consider CVE-2026-64434 an immediate threat requiring urgent mitigation.

Attack Complexity Details

  • Attack Complexity: Low
    Exploits can be performed without significant complexity or special conditions.
  • Attack Vector: Adjacent_network
    Attack Vector Under Analysis
  • Privileges Required: None
    No privileges are required for exploitation.
  • Scope: Unchanged
    Exploit remains within the originally vulnerable component.
  • User Interaction: None
    No user interaction is necessary for exploitation.

CVE-2026-64434 Details

Status: Analyzed

Last updated: 🕕 03 Sep 2026, 18:22 UTC
Originally published on: 🕙 25 Jul 2026, 10:17 UTC

Time between publication and last update: 40 days

CVSS Release: version 3

CVSS3 Source

416baaa9-dc9f-4396-8d5f-8c081fb06d67

CVSS3 Type

Secondary

CVSS3 Vector

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVE-2026-64434 Vulnerability Summary

CVE-2026-64434: In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix UAF in channel timeout by holding conn ref l2cap_chan_timeout() runs asynchronously and accesses chan->conn. If the connection is torn down while the timer is running or pending, chan->conn can be freed, leading to a use-after-free when the timer worker attempts to lock conn->lock: | BUG: KASAN: slab-use-after-free in instrument_atomic_read_write include/linux/instrumented.h:112 [inline] | BUG: KASAN: slab-use-after-free in atomic_long_try_cmpxchg_acquire include/linux/atomic/atomic-instrumented.h:4456 [inline] | BUG: KASAN: slab-use-after-free in __mutex_trylock_fast kernel/locking/mutex.c:161 [inline] | BUG: KASAN: slab-use-after-free in mutex_lock+0x4f/0xa0 kernel/locking/mutex.c:318 | Write of size 8 at addr ffff8881298d9550 by task kworker/2:1/83 | | CPU: 2 UID: 0 PID: 83 Comm: kworker/2:1 Not tainted 7.1.0-rc6-next-20260601-dirty #6 PREEMPT(full) | Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.17.0-debian-1.17.0-1 04/01/2014 | Workqueue: events l2cap_chan_timeout | Call Trace: | <TASK> | instrument_atomic_read_write include/linux/instrumented.h:112 [inline] | atomic_long_try_cmpxchg_acquire include/linux/atomic/atomic-instrumented.h:4456 [inline] | __mutex_trylock_fast kernel/locking/mutex.c:161 [inline] | mutex_lock+0x4f/0xa0 kernel/locking/mutex.c:318 | l2cap_chan_timeout+0x5d/0x1b0 net/bluetooth/l2cap_core.c:422 | process_one_work kernel/workqueue.c:3326 [inline] | process_scheduled_works+0x7c8/0xfb0 kernel/workqueue.c:3409 | worker_thread+0x8a9/0xcf0 kernel/workqueue.c:3490 | kthread+0x346/0x430 kernel/kthread.c:436 | ret_from_fork+0x1a3/0x470 arch/x86/kernel/process.c:158 | ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245 | </TASK> | | Allocated by task 320: | l2cap_conn_add+0xa7/0x820 net/bluetooth/l2cap_core.c:7075 | l2cap_connect_cfm+0xdb/0xd70 net/bluetooth/l2cap_core.c:7452 | hci_connect_cfm include/net/bluetooth/hci_core.h:2139 [inline] | hci_remote_features_evt+0x52f/0x9f0 net/bluetooth/hci_event.c:3760 | hci_event_func net/bluetooth/hci_event.c:7796 [inline] | hci_event_packet+0x561/0xa70 net/bluetooth/hci_event.c:7847 | hci_rx_work+0x370/0x890 net/bluetooth/hci_core.c:4040 | process_one_work kernel/workqueue.c:3326 [inline] | process_scheduled_works+0x7c8/0xfb0 kernel/workqueue.c:3409 | worker_thread+0x8a9/0xcf0 kernel/workqueue.c:3490 | kthread+0x346/0x430 kernel/kthread.c:436 | ret_from_fork+0x1a3/0x470 arch/x86/kernel/process.c:158 | ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245 | | Freed by task 322: | hci_disconn_cfm include/net/bluetooth/hci_core.h:2154 [inline] | hci_conn_hash_flush+0x101/0x1f0 net/bluetooth/hci_conn.c:2736 | hci_dev_close_sync+0x889/0xde0 net/bluetooth/hci_sync.c:5405 | hci_dev_do_close net/bluetooth/hci_core.c:502 [inline] | hci_unregister_dev+0x1f7/0x370 net/bluetooth/hci_core.c:2679 | vhci_release+0x12a/0x180 drivers/bluetooth/hci_vhci.c:690 | __fput+0x369/0x890 fs/file_table.c:510 | task_work_run+0x160/0x1d0 kernel/task_work.c:233 | get_signal+0xf5b/0x1120 kernel/signal.c:2810 | arch_do_signal_or_restart+0x4d/0x600 arch/x86/kernel/signal.c:337 | __exit_to_user_mode_loop kernel/entry/common.c:64 [inline] | exit_to_user_mode_loop+0x85/0x510 kernel/entry/common.c:98 | do_syscall_64+0x263/0x3d0 arch/x86/entry/syscall_64.c:100 | entry_SYSCALL_64_after_hwframe+0x77/0x7f | | The buggy address belongs to the object at ffff8881298d9400 | which belongs to the cache kmalloc-512 of size 512 | The buggy address is located 336 bytes inside of | freed 512-byte region [ffff8881298d9400, ffff8881298d9600) Fix it by having chan->conn hold a reference to l2cap_conn (via l2cap_conn_get) when the channel is added to the connection, and releasing it in the channel destructor. This ensures the l2cap_conn remains alive as long as the channel exists. A new FLAG_DEL channel flag is introduced to indicate that the ch ---truncated---

Assessing the Risk of CVE-2026-64434

Access Complexity Graph

The exploitability of CVE-2026-64434 depends on two key factors: attack complexity (the level of effort required to execute an exploit) and privileges required (the access level an attacker needs).

Exploitability Analysis for CVE-2026-64434

With low attack complexity and no required privileges, CVE-2026-64434 is an easy target for cybercriminals. Organizations should prioritize immediate mitigation measures to prevent unauthorized access and data breaches.

Understanding AC and PR

A lower complexity and fewer privilege requirements make exploitation easier. Security teams should evaluate these aspects to determine the urgency of mitigation strategies, such as patch management and access control policies.

Attack Complexity (AC) measures the difficulty in executing an exploit. A high AC means that specific conditions must be met, making an attack more challenging, while a low AC means the vulnerability can be exploited with minimal effort.

Privileges Required (PR) determine the level of system access necessary for an attack. Vulnerabilities requiring no privileges are more accessible to attackers, whereas high privilege requirements limit exploitation to authorized users with elevated access.

CVSS Score Breakdown Chart

Above is the CVSS Sub-score Breakdown for CVE-2026-64434, illustrating how Base, Impact, and Exploitability factors combine to form the overall severity rating. A higher sub-score typically indicates a more severe or easier-to-exploit vulnerability.

CIA Impact Analysis

Below is the Impact Analysis for CVE-2026-64434, showing how Confidentiality, Integrity, and Availability might be affected if the vulnerability is exploited. Higher values usually signal greater potential damage.

  • Confidentiality: High
    Exploiting CVE-2026-64434 can result in unauthorized access to sensitive data, severely compromising data privacy.
  • Integrity: High
    CVE-2026-64434 could allow unauthorized modifications to data, potentially affecting system reliability and trust.
  • Availability: High
    CVE-2026-64434 can disrupt system operations, potentially causing complete denial of service (DoS).

CVE-2026-64434 References

External References

CWE Common Weakness Enumeration

CWE-416

Vulnerable Configurations

  • cpe:2.3:o:linux:linux_kernel:5.10.259:*:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:5.10.259:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:5.10.260:*:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:5.10.260:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:5.10.261:*:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:5.10.261:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:5.10.262:*:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:5.10.262:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:5.10.263:*:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:5.10.263:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:5.10.264:*:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:5.10.264:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:5.15.210:*:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:5.15.210:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:5.15.211:*:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:5.15.211:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:5.15.212:*:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:5.15.212:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:5.15.213:*:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:5.15.213:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:5.15.214:*:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:5.15.214:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:5.15.215:*:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:5.15.215:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:6.1.176:*:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:6.1.176:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:6.1.177:*:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:6.1.177:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:6.1.178:*:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:6.1.178:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:6.1.179:*:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:6.1.179:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:6.1.180:*:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:6.1.180:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:6.1.181:*:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:6.1.181:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:6.1.182:*:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:6.1.182:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:6.6.143:*:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:6.6.143:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:6.6.144:*:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:6.6.144:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:6.12.93:*:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:6.12.93:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:6.12.94:*:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:6.12.94:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:6.12.95:*:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:6.12.95:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:6.12.96:*:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:6.12.96:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:6.18.35:*:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:6.18.35:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:6.18.36:*:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:6.18.36:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:6.18.37:*:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:6.18.37:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:6.18.38:*:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:6.18.38:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:7.0.12:*:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:7.0.12:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:7.0.13:*:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:7.0.13:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:7.0.14:*:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:7.0.14:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:7.0:rc1:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:7.0:rc1:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:7.0:rc2:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:7.0:rc2:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:7.0:rc3:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:7.0:rc3:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:7.0:rc4:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:7.0:rc4:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:7.0:rc5:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:7.0:rc5:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:7.0:rc6:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:7.0:rc6:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:7.0:rc7:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:7.0:rc7:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:7.1.1:*:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:7.1.1:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:7.1.2:*:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:7.1.2:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:7.1.3:*:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:7.1.3:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:7.1:-:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:7.1:-:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:7.1:rc6:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:7.1:rc6:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:7.1:rc7:*:*:*:*:*:*
    cpe:2.3:o:linux:linux_kernel:7.1:rc7:*:*:*:*:*:*

Protect Your Infrastructure against CVE-2026-64434: Combat Critical CVE Threats

Stay updated with real-time CVE vulnerabilities and take action to secure your systems. Enhance your cybersecurity posture with the latest threat intelligence and mitigation techniques. Develop the skills necessary to defend against CVEs and secure critical infrastructures. Join the top cybersecurity professionals safeguarding today's infrastructures.

Other 5 Recently Published CVEs Vulnerabilities

  • CVE-2026-97318 – The Giveaways and Contests by RafflePress WordPress plugin before 1.12.27 does not properly validate a giveaway's parent page URL before saving it...
  • CVE-2026-97317 – The Giveaways and Contests by RafflePress WordPress plugin before 1.12.27 does not remove the reCAPTCHA secret key from the giveaway settings it e...
  • CVE-2026-94298 – The BuildKit WordPress plugin before 1.0.29 does not properly sanitise and escape data submitted by contributor-level users before storing it and ...
  • CVE-2026-92820 – The Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary file operations in all versions up to, and including, 3.3.34 via the...
  • CVE-2026-92174 – The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.73.2 via the 'them...