Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2026-64054
Linux Linux — net: shaper: reject duplicate leaves in GROUP request
AV AC PR UI S C I A CVSS EPSS %ile KEV
L L L N U H H H 7.8 .0013 2.0 —
AFFECTED
Product Versions Fixed
Linux 5d5d4700e75d861e83bf18eb6bf66ff90f85fe4e – —
Linux 6.13 – 6.18.34
TIMELINE
Jul 19 Reserved by Linux
Jul 19 Published (CNA: Linux)
Sep 2 ENRICHED — CVE-2026-64054 (Linux). Received CVSS 7.8 and CPE data from NVD.
Description
In the Linux kernel, the following vulnerability has been resolved:
net: shaper: reject duplicate leaves in GROUP request
net_shaper_nl_group_doit() does not deduplicate NET_SHAPER_A_LEAVES
entries. When userspace supplies the same leaf handle twice, the same
old-parent pointer lands twice in old_nodes[]. The cleanup loop double
frees the parent. Of course the same parent may still be in old_nodes[]
twice if we are moving multiple of its leaves.
Note that this patch also implicitly fixes the fact that the
i >= leaves_count path forgets to set ret.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| July 19, 2026 | Reserved | Reserved by Linux |
| July 19, 2026 | Published | Published (CNA: Linux) |
| September 2, 2026 | ENRICHED | ENRICHED — CVE-2026-64054 (Linux). Received CVSS 7.8 and CPE data from NVD. |
Affected
Affected products and packages — 2 rows
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| Linux | Linux | — | 5d5d4700e75d861e83bf18eb6bf66ff90f85fe4e | — |
| Linux | Linux | — | 6.13 | 6.18.34 |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-64054 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.