Answer in brief
CVE-2026-64033 records a Unknown severity vulnerability in RDMA/rtrs: Fix use-after-free in path file creation cleanup. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2026-64033 records a Unknown severity vulnerability in RDMA/rtrs: Fix use-after-free in path file creation cleanup. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=bab17b761c8974a869b04462be5d4dd9aad366b4 <01e42aabaf7632beb4bf235c7238b96c746d4144 || >=ae4c81644e9105d9f7f713bb0d444737bb6a0cf1 <548f3956e53a7f7bde912d8129010b8986d5e602 || >=ae4c81644e9105d9f7f713bb0d444737bb6a0cf1 <00904a73272b9f3ef3952fe69a833909dccad1ef || >=ae4c81644e9105d9f7f713bb0d444737bb6a0cf1 <92060ab1c5115674cf319175550f85f68405121f || >=ae4c81644e9105d9f7f713bb0d444737bb6a0cf1 <eae62c5451e67e8b033c1681fd3b85d7e9a9a28f || >=ae4c81644e9105d9f7f713bb0d444737bb6a0cf1 <b0e9706fb2859064bb6c677554c4d20c713aa8e0 || >=ae4c81644e9105d9f7f713bb0d444737bb6a0cf1 <5b74373390113fba798a76b483837029ab010fef || >=5.15.61 <5.15.209 | 01e42aabaf7632beb4bf235c7238b96c746d4144, 548f3956e53a7f7bde912d8129010b8986d5e602, 00904a73272b9f3ef3952fe69a833909dccad1ef, 92060ab1c5115674cf319175550f85f68405121f, eae62c5451e67e8b033c1681fd3b85d7e9a9a28f, b0e9706fb2859064bb6c677554c4d20c713aa8e0, 5b74373390113fba798a76b483837029ab010fef, 5.15.209 |
| Linux/Linuxgeneric | 5.17 | Not reported |
Published upstream
Jul 19, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: RDMA/rtrs: Fix use-after-free in path file creation cleanup In the error path of rtrs_srv_create_path_files(), the sysfs root folders may already have been created and srv_path->kobj may already have been initialized. If a later step fails, the cleanup currently calls kobject_put(&srv_path->kobj) before rtrs_srv_destroy_once_sysfs_root_folders(srv_path). kobject_put() may drop the last reference to srv_path->kobj and invoke the release callback, rtrs_srv_release(), which frees srv_path. The following call to rtrs_srv_destroy_once_sysfs_root_folders(srv_path) then dereferences srv_path internally to access srv_path->srv, resulting in a use-after-free. This failure path is reached before rtrs_srv_create_path_files() returns success, so the successful-path lifetime handling is not involved. Fix this by destroying the sysfs root folders before calling kobject_put(&srv_path->kobj), so srv_path is still valid while the helper accesses it. This issue was found by a static analysis tool I am developing.
Quoted source text, attributed separately from HOL analysis.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=bab17b761c8974a869b04462be5d4dd9aad366b4 <01e42aabaf7632beb4bf235c7238b96c746d4144 || >=ae4c81644e9105d9f7f713bb0d444737bb6a0cf1 <548f3956e53a7f7bde912d8129010b8986d5e602 || >=ae4c81644e9105d9f7f713bb0d444737bb6a0cf1 <00904a73272b9f3ef3952fe69a833909dccad1ef || >=ae4c81644e9105d9f7f713bb0d444737bb6a0cf1 <92060ab1c5115674cf319175550f85f68405121f || >=ae4c81644e9105d9f7f713bb0d444737bb6a0cf1 <eae62c5451e67e8b033c1681fd3b85d7e9a9a28f || >=ae4c81644e9105d9f7f713bb0d444737bb6a0cf1 <b0e9706fb2859064bb6c677554c4d20c713aa8e0 || >=ae4c81644e9105d9f7f713bb0d444737bb6a0cf1 <5b74373390113fba798a76b483837029ab010fef || >=5.15.61 <5.15.209 | 01e42aabaf7632beb4bf235c7238b96c746d4144, 548f3956e53a7f7bde912d8129010b8986d5e602, 00904a73272b9f3ef3952fe69a833909dccad1ef, 92060ab1c5115674cf319175550f85f68405121f, eae62c5451e67e8b033c1681fd3b85d7e9a9a28f, b0e9706fb2859064bb6c677554c4d20c713aa8e0, 5b74373390113fba798a76b483837029ab010fef, 5.15.209 |
| Linux/Linuxgeneric | 5.17 | Not reported |
Published upstream
Jul 19, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: RDMA/rtrs: Fix use-after-free in path file creation cleanup In the error path of rtrs_srv_create_path_files(), the sysfs root folders may already have been created and srv_path->kobj may already have been initialized. If a later step fails, the cleanup currently calls kobject_put(&srv_path->kobj) before rtrs_srv_destroy_once_sysfs_root_folders(srv_path). kobject_put() may drop the last reference to srv_path->kobj and invoke the release callback, rtrs_srv_release(), which frees srv_path. The following call to rtrs_srv_destroy_once_sysfs_root_folders(srv_path) then dereferences srv_path internally to access srv_path->srv, resulting in a use-after-free. This failure path is reached before rtrs_srv_create_path_files() returns success, so the successful-path lifetime handling is not involved. Fix this by destroying the sysfs root folders before calling kobject_put(&srv_path->kobj), so srv_path is still valid while the helper accesses it. This issue was found by a static analysis tool I am developing.
Quoted source text, attributed separately from HOL analysis.