THREAT OPS › Threat News › [NVD] CVE-2026-64354 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved:
bpf: Validate BTF repeated field counts before expansion
btf_parse_struct_metas() walks user-supplied BTF during BPF_BTF_LOAD,
and btf_repeat_fields() expands repeatable fields from array elements
into the fixe
[NVD] CVE-2026-64354 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: bpf: Validate BTF repeated field counts before expansion btf_parse_struct_metas() walks user-supplied BTF during BPF_BTF_LOAD, and btf_repeat_fields() expands repeatable fields from array elements into the fixe
CVE-2026-64354 CVSS: 7.8 HIGH Published: 2026-07-25T10:17:17.810
In the Linux kernel, the following vulnerability has been resolved:
bpf: Validate BTF repeated field counts before expansion
btf_parse_struct_metas() walks user-supplied BTF during BPF_BTF_LOAD, and btf_repeat_fields() expands repeatable fields from array elements into the fixed BTF_FIELDS_MAX scratch array used by btf_parse_field
Indicators of compromise
- CVE-2026-64354cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-64354