Linux Linux Kernel
CVE-2026-64299
In the Linux kernel, the following vulnerability has been resolved: tracing: Prevent out-of-bounds read in glob matching String event fields are not necessarily NUL-terminated, so the filter predicate functions (filter_pred_string(), filter_pred_strloc() and filter_pred_strrelloc()) pass the field length to the regex match callbacks, and the length-aware matchers honour it. regex_match_glob() was the exception: it ignored the length and called glob_match(), which scans the string until it hits a NUL byte. Some string fields are not NUL-terminated. One example is the dynamic char array of the xfs_* namespace tracepoints, which is copied without a trailing NUL. For such a field, glob matching reads past the end of the event field, causing a KASAN slab-out-of-bounds read in glob_match(), reached via regex_match_glob() and filter_match_preds() from the xfs_lookup tracepoint. Add a length-bounded glob_match_len() and use it from regex_match_glob() so glob matching always stops at the field boundary. The matching loop is factored into a shared helper so glob_match() keeps its behaviour.
What this means for your business
- It affects Linux Kernel. It matters if your company, or a supplier that handles your data, runs it.
- An attacker can use it only with access to the machine itself, with an ordinary user login, and without anyone at your company clicking anything.
- FIRST's prediction model gives it a 0.2% chance of attack attempts being seen in the next 30 days, ranking above 6% of all known flaws.
What to do
- 1Check whether your company or your suppliers run Linux Kernel, and which version. The affected versions are listed further down this page.
- 2If you do, apply the vendor's fix. A patch or vendor advisory has been published.
Fastnexa security experts
Not sure if your company is exposed to CVE-2026-64299?
Tell us where you run Linux Linux Kernel and a Fastnexa penetration tester will check whether this flaw, or others like it, can be used against your websites, apps and network.
The full test is free for our first 10 founding clients until 31 December 2026. See the offer
Think you’ve already been hit? Don’t wait on a form: call or WhatsApp +1 (732) 454 2616. We reply within 1 hour, 24/7. Emergency help →
Scoring
- CVSS
- 7.1 (v3.1)
- Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H- Weakness
- CWE-125
- Assigned by
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Dates
- Published
- 2026-07-25
- Last modified
- 2026-09-03
- Sources
- NVD
Affected products
- Linux Linux Kernel4.10 - 5.10.261, 5.11 - 5.15.212, 5.16 - 6.1.178, 6.2 - 6.6.145, 6.7 - 6.12.96, 6.13 - 6.18.39, 6.19 - 7.1.4, 7.2
As listed in the NVD configuration data. Not a statement about your estate.
References
- https://git.kernel.org/stable/c/0a6070839b1ef276d5b05bedfb787743e140fb17
- https://git.kernel.org/stable/c/265f3a690f6c7d69ef7d2ca50b04b4853a211df3
- https://git.kernel.org/stable/c/2dad64a97e1df47f5d9ccb17fa319aa348617226
- https://git.kernel.org/stable/c/35ae19764eabfe9c29029d3b5713c86e6855acdf
- https://git.kernel.org/stable/c/56d4c9ab84714eebb285a2fee68aaedf81e3ef15
- https://git.kernel.org/stable/c/e5d5f3bd053a5f14787526c9f0f55ef900d43ac6
- https://git.kernel.org/stable/c/ebb55902856973906c8bb339a3a34824ed4a5086
- https://git.kernel.org/stable/c/ee5b8888d3248618251fb69a2fad92afcb81557e