CVE-2026-63974
Multiple vulnerabilities have been discovered in Ubuntu Linux kernel. Some of them allow an attacker to cause privilege escalation, breach of data confidentiality and breach of data integrity.
CSIRTS triage
- What
- Multiple kernel vulnerabilities enable privilege escalation and breach of data confidentiality and integrity.
- Who is affected
- Ubuntu Linux kernel users running affected versions.
- Urgency
- Unknown severity but privilege escalation impact is critical; apply updates promptly.
- Action
- Install the latest Ubuntu Linux kernel security update (August 21, 2026).
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2026-63974
Get an email if CVE-2026-63974 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.32% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 25% of all EPSS-scored CVEs.
Advisory coverage (10)
- unknownMultiple vulnerabilities in Ubuntu Linux kernel (August 21, 2026)cert-fr-avis · 2026-08-21
- unknownMultiple vulnerabilities in SUSE Linux kernel (August 21, 2026)cert-fr-avis · 2026-08-21
- unknownUSN-8664-1: Linux kernel (NVIDIA BaseOS) vulnerabilitiesubuntu · 2026-08-20
- unknownUSN-8663-1: Linux kernel (NVIDIA) vulnerabilitiesubuntu · 2026-08-20
- highUSN-8618-1: Linux kernel vulnerabilitiesubuntu · 2026-07-28
- highUSN-8603-1: Linux kernel (Azure) vulnerabilitiesubuntu · 2026-07-24
- unknownMultiple vulnerabilities in Ubuntu Linux kernel (July 24, 2026)cert-fr-avis · 2026-07-24
- highUSN-8593-1: Linux kernel vulnerabilitiesubuntu · 2026-07-23
- highCVE-2026-63974: In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: Set H…nvd · 2026-07-19
- criticalCVE-2026-63974: Bluetooth: hci_sync: Set HCI_CMD_DRAIN_WORKQUEUE during device closemsrc · 2026-07-14
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-63974)