The Tails project shipped Tails 7.10.1 as an emergency release on August 5, 2026. This update addresses two critical security flaws – one in the Linux kernel and one in the expat XML library – either of which could let an attacker take full control of a user’s system and destroy their anonymity.
Linux kernel flaw: CVE-2026-64560
The most urgent fix targets CVE-2026-64560 (CVSS 7.0), a use-after-free bug in the Linux kernel’s CPU timer handling. A race condition triggers the flaw when a process deletes a timer while another operation still holds a reference to it. The kernel then accesses already-freed memory, opening the door to privilege escalation.
The Tails team explains the real-world risk plainly: “If a malicious website that you visit is able to exploit CVE-2026-64560, they might take full control of your Tails and deanonymize you.” Tails 7.10.1 ships the Linux kernel updated to version 6.12.100, which closes the hole. The team notes the attack is “very unlikely but could be performed by a strong attacker, such as a government or a hacking firm,” and reports no confirmed in-the-wild exploitation to date.
Expat XML library: DSA-6404-1
The second fix updates the expat XML library to version 2.8.2, addressing the set of vulnerabilities tracked as DSA-6404-1. Applications that use expat – including LibreOffice, Audacity, and Git – are all affected. An attacker who tricks a user into opening a crafted malicious file could chain one of these bugs to gain administrator privileges and deanonymize the user. No confirmed exploitation has been reported for these flaws either.
Additional improvements
Beyond security patches, Tails 7.10.1 brings two quality-of-life changes. Automatic upgrades now compress with zstd, cutting startup time. USB images and upgrade packages are also 70 MB smaller after unused firmware was removed.
Update now
All Tails users should update immediately. The Tails project recommends upgrading through the built-in automatic upgrade mechanism. New users can follow the full Tails installation guide to get started on a clean USB drive.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.