[UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellen
Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um den Speicher zu beschädigen, einen Denial-of-Service-Zustand auszulösen, Daten zu manipulieren oder vertrauliche Informationen offenzulegen.
CSIRTS triage
- What
- Multiple vulnerabilities in the Linux Kernel allow memory corruption, denial-of-service, data manipulation, and information disclosure.
- Who is affected
- Systems running affected Linux Kernel versions.
- Urgency
- Medium severity; not currently exploited but affects core OS stability and security.
- Action
- Apply kernel security updates from your distribution when available.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Linux Kernel
Get an email when a new Linux Kernel advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2659
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-645660.35% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 28% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-645670.12% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 2% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-645680.12% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 2% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-645690.17% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 7% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-645700.16% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 5% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-645710.17% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 7% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-645720.20% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 10% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-645730.16% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 6% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-645740.12% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 2% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-645750.12% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 2% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-64566 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-64567 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-64568 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-64569 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-64570 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-64571 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-64572 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-64573 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-64574 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-64575 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-64576 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-64577 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-64578 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-64579 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-64580 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-64581 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownMultiples vulnérabilités dans le noyau Linux de Debian (04 septembre 2026)cert-fr-avis
- unknownDSA-6477-1 linux - security updatedebian
- unknownMultiple vulnerabilities in Debian LTS Linux kernel (August 21, 2026)cert-fr-avis
- unknownMultiple vulnerabilities in Debian Linux kernel (August 14, 2026)cert-fr-avis
- mediumCVE-2026-64581: xfrm: fix sk_dst_cache double-free in xfrm_user_policy()msrc
- mediumCVE-2026-64574: wifi: mac80211: tear down new links on vif update error pathmsrc
- mediumCVE-2026-64576: nexthop: initialize extack in nh_res_bucket_migrate()msrc
- mediumCVE-2026-64579: xfrm: policy: preallocate inexact bins before xfrm_hash_rebuild reinsertmsrc
- mediumCVE-2026-64569: mpls: fix NULL deref in mpls_valid_fib_dump_req() on CONFIG_INET=nmsrc
- lowCVE-2026-64571: wifi: p54: validate RX frame length in p54_rx_eeprom_readback()msrc
- mediumCVE-2026-64572: ipv4: fib: free fib_alias with kfree_rcu() on insert error pathmsrc
- highCVE-2026-64577: gtp: check skb_pull_data() return in gtp1u_send_echo_resp()msrc
Recent advisories for Linux Kernel
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- medium[UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Servicecert-bund · 2026-09-14
- high[UPDATE] [hoch] Linux Kernel: Mehrere Schwachstellencert-bund · 2026-09-14
- high[UPDATE] [hoch] Linux Kernel: Mehrere Schwachstellencert-bund · 2026-09-14
- medium[UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellencert-bund · 2026-09-14
- medium[UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellencert-bund · 2026-09-14
- high[UPDATE] [hoch] Linux Kernel: Mehrere Schwachstellencert-bund · 2026-09-14
More from CERT-Bund (BSI) Security Advisories
- medium[NEU] [mittel] Microsoft Edge: Schwachstelle ermöglicht Cross-Site Scripting2026-09-14
- medium[NEU] [mittel] Citrix Systems Workspace App Windows: Mehrere Schwachstellen ermöglichen nicht spezifizierten A…2026-09-14
- medium[NEU] [mittel] wpa_supplicant: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen2026-09-14
- medium[NEU] [mittel] WP Royal Royal Elementor Addons: Schwachstelle ermöglicht Offenlegung von Informationen2026-09-14
- low[UPDATE] [niedrig] 7-Zip: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen2026-09-14