Red Hat disclosed CVE-2026-64561, a moderate-severity flaw in the Linux kernel's KVM subsystem caused by improper validation of MMU page roots after those pages are made available. The bug can cause KVM to map memory into an invalid root, allowing child shadow pages to inherit an invalid state and potentially leading to system instability or denial of service in virtualized environments. Red Hat scored the issue at CVSS 7.0, while cve.org lists 8.8, and classified it as CWE-825 Expired Pointer Dereference; Red Hat said multiple Red Hat Enterprise Linux kernel packages were fixed through July 2026 errata, while RHEL 6 was not affected because the vulnerable code is absent.
In a separate kernel advisory, RHSA-2026:49030, Red Hat released updated RHEL 10.0 kernel packages to fix two additional KVM-related vulnerabilities, CVE-2025-40026 and CVE-2026-63807, across standard, Extended Update Support, and 4-year update channels. The advisory lists fixed packages as kernel-6.12.0-55.94.1.el10_0 for x86_64, s390x, ppc64le, and aarch64, including associated CodeReady Linux Builder repositories, and noted that affected systems must be rebooted after installation for the protections to take effect.

See real exploitation activity before you spend the cycle.
6 events from the most recent confirmed update back to the earliest known activity.
Red Hat published security advisory RHSA-2026:49030 on July 31, 2026, making updated RHEL 10.0 kernel packages available and requiring a reboot after installation. The advisory explicitly describes fixes for CVE-2025-40026 and CVE-2026-63807, and also lists CVE-2026-64561 in its CVE section.
Red Hat lists CVE-2026-64561 as fixed in several kernel advisories released on July 24, 2026, covering RHEL 8 kernel, RHEL 8 kernel-rt, RHEL 9 kernel, and RHEL 10 kernel. The flaw affects KVM in the Linux kernel and can cause instability or denial of service in virtualized environments.
Red Hat last modified the CVE-2026-64561 record on August 13, 2026. The record notes affected and fixed RHEL kernel packages and states that RHEL 6 is not affected because the vulnerable code is not present.
Red Hat published its CVE record for CVE-2026-64561 on August 4, 2026, describing a KVM flaw caused by improper validation of MMU page roots after those pages are made available. Red Hat rated the issue Moderate and assigned it a CVSS v3 score of 7.0.
Red Hat also lists CVE-2026-64561 as fixed on July 31, 2026, in RHSA-2026:48386 for RHEL 9.4 Update Services for SAP Solutions and RHSA-2026:49031 for RHEL 9.6 Extended Update Support. The same date includes the RHEL 10.0 Extended Update Support fix tracked in RHSA-2026:49030.
On July 29, 2026, Red Hat lists CVE-2026-64561 as fixed in RHSA-2026:47869 for RHEL 8.8 Telecommunications Update Service and RHEL 8.8 Update Services for SAP Solutions kernel packages.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.