Tails 7.10.1: Emergency Patch for CVE-2026-64560 That Could Deanonymize Users

Tails 7.10.1 emergency patch for CVE-2026-64560 Linux kernel POSIX CPU timer race condition allowing Tor Browser privilege escalation and user deanonymization

Users of anonymous operating systems typically rely on the guarantee that no single program running within the environment can betray their true identity. Sometimes, however, a solitary flaw in the Linux kernel is sufficient to shatter that assurance. The Tails development team has released an emergency update addressing a severe vulnerability that, when combined with a separate bug in Tor Browser, could allow a malicious website to unmask a user’s identity.

The Vulnerability: CVE-2026-64560

The flaw, catalogued as CVE-2026-64560 and scored 7.8 under CVSS 3.1, resides in the POSIX CPU timer subsystem of the Linux kernel. It triggers an infrequent but exploitable race condition. Under the right circumstances, an already-compromised Tor Browser process can leverage this condition to escalate its privileges to root level within the host system.

Once root access is obtained, a threat actor achieves complete operational control over the Tails environment – including the ability to deanonymize the user by bypassing the protections Tor is specifically designed to provide.

What Tails Is and Who Uses It

Tails is a portable Linux distribution that boots from a USB drive and leaves no persistent trace on the host machine after shutdown. It is the tool of choice for journalists, political activists, and individuals seeking to protect their identities from surveillance or to circumvent censorship. The embedded Tor Browser routes all internet traffic through the Tor anonymity network as a foundational privacy guarantee.

How Long the Flaw Existed

The vulnerability was introduced in Linux kernel version 5.7, released in May 2020 – meaning it persisted undetected for more than six years before being discovered last week. The Tor Project has stated that executing this attack successfully demands considerable resources and sophistication. Threat actors capable of mounting it are likely state-level intelligence services or well-funded commercial exploit developers. No confirmed cases of active exploitation have been reported.

Additional Vulnerabilities Patched in the Same Release

The emergency release addressed several further privilege escalation flaws beyond CVE-2026-64560. One involves the Expat XML parsing library. If a user can be socially engineered into opening a malicious file within LibreOffice, Audacity, or Git, an attacker can similarly obtain root privileges and deanonymize the victim. The attack surface, while requiring user interaction, is realistic enough to warrant the emergency response.

How to Update Safely

The Tails development team strongly recommends upgrading to version 7.10.1 as promptly as possible. Users should apply the update through Tails’ built-in automatic upgrade mechanism or via the manual upgrade process. Both methods preserve data stored in the Persistent Storage partition on the USB drive. A full reinstallation of Tails, by contrast, will erase all data in Persistent Storage and should be avoided unless necessary.

Support Our Threat Intelligence

If you find our technology report and cybersecurity news helpful, consider supporting our work.

Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Leave a Reply