CVE-2026-64306
Published Jul 25, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: crypto: drbg - Fix returning success on failure in CTR_DRBG drbg_ctr_generate() sometimes returns success when it fails, leaving the output buffer uninitialized. Fix it.
Is your site exposed to CVE-2026-64306?
Run a free security scan — no signup, results in seconds.
EPSS — Exploit Prediction
0.0022
Probability of exploitation
0.13%
Percentile rank
EPSS estimates the probability that this vulnerability will be exploited in the wild within the next 30 days. A higher score means more likely to be exploited.
References
Other References
https://git.kernel.org/stable/c/074db6db03a0aaa78f05ca9d4838053713796665
https://git.kernel.org/stable/c/23b8b188cb32e5531d0f8d3af9506f8959cb369e
https://git.kernel.org/stable/c/39a31ad9e2a5ed7e9c9c6f711dca96c8c8f5f26b
https://git.kernel.org/stable/c/75597e8774f319152744d24e0683d9393540a951
https://git.kernel.org/stable/c/7b03312491f9fe6ba4d60c4023e7e61d2d1fed96
https://git.kernel.org/stable/c/a9e886f73dd717027028bb7e3bbca93601ecdfc7
https://git.kernel.org/stable/c/bbbac12083eff489b35d848332f0dff311131344
https://git.kernel.org/stable/c/cc42fb40171c249bb859071d81b4eb007398a0bc
Frequently Asked Questions
What is CVE-2026-64306? +
In the Linux kernel, the following vulnerability has been resolved:
crypto: drbg - Fix returning success on failure in CTR_DRBG
drbg_ctr_generate() sometimes returns success when it fails, leaving the
output buffer uninitialized. Fix it.
How do I check if I'm vulnerable to CVE-2026-64306? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.