Answer in brief
CVE-2026-64073 records a High severity (CVSS 7.8) vulnerability in irq_work: Fix use-after-free in irq_work_single() on PREEMPT_RT. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 7.8. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Product | Affected versions | Fixed versions |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | Not reported | Not reported |
| cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:* | Not reported | Not reported |
| cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:* | Not reported | Not reported |
| cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:* | Not reported | Not reported |
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=810979682ccc98dbd83f341c18a2e556c30a7164 <2dc79362302922cb18f35e262712b5e58de65442 || >=810979682ccc98dbd83f341c18a2e556c30a7164 <eef4f71b46a9929ac33e968538c9dd5d96a02460 || >=810979682ccc98dbd83f341c18a2e556c30a7164 <684a78183c54c23e70d1cba320f7fc184604210b || >=810979682ccc98dbd83f341c18a2e556c30a7164 <18c0456ea2615b1a743a6db739c74411c3b42bc6 || >=810979682ccc98dbd83f341c18a2e556c30a7164 <81b582784518196eff1050212a046bc29d3a05dd || >=810979682ccc98dbd83f341c18a2e556c30a7164 <91840be8f710370607f949a627e070896faeddb8 | 2dc79362302922cb18f35e262712b5e58de65442, eef4f71b46a9929ac33e968538c9dd5d96a02460, 684a78183c54c23e70d1cba320f7fc184604210b, 18c0456ea2615b1a743a6db739c74411c3b42bc6, 81b582784518196eff1050212a046bc29d3a05dd, 91840be8f710370607f949a627e070896faeddb8 |
| Linux/Linuxgeneric | 5.16 | Not reported |
Published upstream
Jul 19, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 3, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: irq_work: Fix use-after-free in irq_work_single() on PREEMPT_RT On PREEMPT_RT, non-HARD irq_work runs in per-CPU kthreads via run_irq_workd(), so irq_work_sync() uses rcuwait() to wait for BUSY==0. After irq_work_single() clears BUSY via atomic_cmpxchg(), it still dereferences @work for irq_work_is_hard() and rcuwait_wake_up(). An irq_work_sync() caller on another CPU that enters after BUSY is cleared can observe BUSY==0 immediately, return, and free the work before those accesses complete — causing a use-after-free. Fix this by wrapping run_irq_workd() in guard(rcu)() so that the entire irq_work_single() execution is within an RCU read-side critical section. Then add synchronize_rcu() in irq_work_sync() after rcuwait_wait_event() to ensure the caller waits for the RCU grace period before returning, preventing premature frees.
Quoted source text, attributed separately from HOL analysis.