Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2026-64353

Published Jul 25, 2026 EPSS 0.17% (6th pctl)

Overview

CVE-2026-64353 is a known-severity vulnerability. It was published on July 25, 2026.

Technical Description

In the Linux kernel, the following vulnerability has been resolved:

bpf: Keep dynamic inner array lookups nullable

An ARRAY_OF_MAPS can use an array created with BPF_F_INNER_MAP as its

inner map template. A concrete inner array with a different max_entries

value can then replace the template.

After a successful outer map lookup, the verifier represents the

resulting map pointer using the inner map template. Const-key lookup

nullness elision consequently uses the template max_entries even though

the runtime helper uses the concrete inner map max_entries.

Do not elide lookup result nullness for maps marked with BPF_F_INNER_MAP,

because the template max_entries does not prove that the key is in bounds

for the concrete runtime map.

Remediation

Check the references section for vendor advisories, patches, and mitigation guidance. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Frequently Asked Questions

What is CVE-2026-64353?

CVE-2026-64353 is a known-severity vulnerability. It was published on July 25, 2026.

How severe is CVE-2026-64353?

CVSS score information is not yet available for this vulnerability. Check back as the CVE record is updated by NVD analysts.

How do I fix or remediate CVE-2026-64353?

Check the references section for vendor advisories, patches, and mitigation guidance. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2026-64353?

CyberStrike's AI-powered security agents can automatically detect CVE-2026-64353 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.