THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-64354 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: bpf: Validate BTF repeated field counts before expansion btf_parse_struct_metas() walks user-supplied BTF during BPF_BTF_LOAD, and btf_repeat_fields() expands repeatable fields from array elements into the fixe

[NVD] CVE-2026-64354 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: bpf: Validate BTF repeated field counts before expansion btf_parse_struct_metas() walks user-supplied BTF during BPF_BTF_LOAD, and btf_repeat_fields() expands repeatable fields from array elements into the fixe

lownvdPublished 2026-07-25

CVE-2026-64354 CVSS: 7.8 HIGH Published: 2026-07-25T10:17:17.810

In the Linux kernel, the following vulnerability has been resolved:

bpf: Validate BTF repeated field counts before expansion

btf_parse_struct_metas() walks user-supplied BTF during BPF_BTF_LOAD, and btf_repeat_fields() expands repeatable fields from array elements into the fixed BTF_FIELDS_MAX scratch array used by btf_parse_field

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-64354