A vulnerability marked as very critical has been reported in Linux Kernel up to 6.18.38/7.1.3. Affected is the function
wait_for_completion_interruptible of the component loongson-rng. This manipulation causes use after free.
This vulnerability is tracked as CVE-2026-64311. The attack is possible to be carried out remotely. No exploit exists.
It is suggested to upgrade the affected component.