---
id: CVE-2026-64015
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  security/keys: fix missed RCU read section on lookup

  Nicholas Carlini reports that the keyring code calls assoc_array_find()
  in find_key_to_update() without holding th…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  security/keys: fix missed RCU read section on lookup

  Nicholas Carlini reports that the keyring code calls assoc_array_find()
  in find_key_to_update() without holding th…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-125
vendor: linux
product: linux_kernel
affected:
  - 'linux_kernel >= 3.13, < 6.1.175'
  - 'linux_kernel >= 6.2, < 6.6.142'
  - 'linux_kernel >= 6.7, < 6.12.92'
  - 'linux_kernel >= 6.13, < 6.18.34'
  - 'linux_kernel >= 6.19, < 7.0.11'
  - linux_kernel = 7.1
patched:
  - linux_kernel 7.0.11
published: '2026-07-19'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T17:09:49.653'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-64015'
references:
  - url: 'https://git.kernel.org/stable/c/43a1e3744548e6fd85873e6fb43e293eb4010694'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/4c5d407ba3ff7f30561ff73ba1b07ed70c864edc'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/50bb3435a5e627bfbdc52eb4536f49f88b3486b8'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/5659e6923cb72f8e18e8b539109ab512455fe195'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/66288dcadf80974436250e9f70ed848836b835b5'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/cefa4265b11176c897a7d9e8e54d89e3701c5584'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
epss: 0.002
epssPercentile: 0.09034
ingestedAt: '2026-10-08T17:56:11.698Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

security/keys: fix missed RCU read section on lookup

Nicholas Carlini reports that the keyring code calls assoc_array_find()
in find_key_to_update() without holding the RCU read lock, while the
assoc_array_gc() code really is designed around removing the node from
the tree and then freeing it after an RCU grace-period.

The regular key handling doesn't see this because holding the keyring
semaphore hides any lifetime issues, but the persistent key handling
uses a different model.

Instead of extending the keyring locking, just do the simple RCU locking
that the assoc_array was designed for.

## Affected

- `linux_kernel >= 3.13, < 6.1.175`
- `linux_kernel >= 6.2, < 6.6.142`
- `linux_kernel >= 6.7, < 6.12.92`
- `linux_kernel >= 6.13, < 6.18.34`
- `linux_kernel >= 6.19, < 7.0.11`
- `linux_kernel = 7.1`

## Remediation

Upgrade past the affected range:

- `linux_kernel 7.0.11`
