CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-64306

mediumCVSS 5.5covered by 2 sourcesfirst seen 2026-07-25
In the Linux kernel, the following vulnerability has been resolved: crypto: drbg - Fix returning success on failure in CTR_DRBG drbg_ctr_generate() sometimes returns success when it fails, leaving the output buffer uninitialized. Fix it.

CSIRTS triage

What
The CTR_DRBG function incorrectly returns success on failure.
Who is affected
Deployments using the crypto subsystem.
Urgency
Remediation is necessary to ensure proper functionality, though no exploitation is reported.
Action
Apply the latest patches for the crypto subsystem.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-64306

Get an email if CVE-2026-64306 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-64306

CVE.org record

Embed the live status

CVE-2026-64306 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-64306 status](https://www.csirts.com/badge/CVE-2026-64306)](https://www.csirts.com/cve/CVE-2026-64306)