CVE- 2026-64582 is a vulnerability in the Linux kernel's RDMA/rxe driver, involving a use-after-free issue that can lead to local privilege escalation. The flaw allows a local attacker to exploit the vulnerability by manipulating a Completion Queue and exploiting a race condition in the `rxe_mmap()` function, gaining root access on affected systems. Its CVSS score is 7.8 (High). A patch is available, and systems are urged to update immediately. Public proof-of-concept exploit code has been released, increasing the urgency for mitigation. No confirmed exploits in the wild have been reported yet.
Linux Kernel RDMA Bug Allows Local Users to Gain Root
CyberSIXT Evidence Panel
Article by CyberSIXT