CVE-2026-64033
In the Linux kernel, the following vulnerability has been resolved: RDMA/rtrs: Fix use-after-free in path file creation cleanup In the error path of rtrs_srv_create_path_files(), the sysfs root folders may already have been created and srv_path->kobj may already have been initialized. If a later step fails, the cleanup currently calls kobject_put(&srv_path->kobj) before rtrs_srv_destroy_once_sysfs_root_folders(srv_path). kobject_put() may drop the last reference to srv_path->kobj and invoke the release callback, rtrs_srv_release(), which frees srv_path. The following call to rtrs_srv_destroy_once_sysfs_root_folders(srv_path) then dereferences srv_path internally to access srv_path->srv, resulting in a use-after-free. This failure path is reached before rtrs_srv_create_path_files() returns success, so the successful-path lifetime handling is not involved. Fix this by destroying the sysfs root folders before calling kobject_put(&srv_path->kobj), so srv_path is still valid while the helper accesses it. This issue was found by a static analysis tool I am developing.
Affected versions
Linux kernel versions
5.15.61,
5.17
and later are affected. Fixed in
5.15.209,
6.1.175,
6.6.142,
6.12.92,
6.18.34,
7.0.11,
7.1
and their respective stable series.
References
7 totalFrequently asked questions
-
What is CVE-2026-64033?
CVE-2026-64033 is a unscored severity Linux kernel vulnerability . It affects Linux kernel versions from 5.15.61 onward and has been patched in 5.15.209, 6.1.175, 6.6.142 and others. CVE-2026-64033 has not been confirmed as actively exploited and is not listed in the CISA KEV catalog.
-
Is there a patch available for CVE-2026-64033?
Yes — CVE-2026-64033 has been patched. Fixed versions include 5.15.209, 6.1.175, 6.6.142 and others. If you are running Linux kernel 5.15.61 or later up to the fix versions, apply the relevant patch for your kernel branch.
-
Is CVE-2026-64033 actively exploited?
No — CVE-2026-64033 has not been confirmed as actively exploited. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.