CVE-2026-64055: Linux Kernel
Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: net: ethernet: cortina: Carry over frag counter The gmac_rx() NAPI poll function assembles packets in an SKB from a ring buffer. If the ring buffer gets completely emptied during a poll cycle, we exit gmac_rx(), but the packet is not yet completely assembled in the SKB, yet the fragment counter frag_nr is reset to zero on the next invocation. Solve this by making the RX fragment counter a part of the port struct, and carry it over between invocations. Reset the fragment counter only right after calling napi_gro_frags(), on error (after calling napi_free_frags()) or if stopping the port. Reset it in some place where not strictly necessary just to emphasize what is going on. This was found by Sashiko during normal patch review.
Affected products
- Linux Linux Kernel: from 4.16, before 5.10.258 (fixed in 5.10.258); from 5.11, before 5.15.209 (fixed in 5.15.209); from 5.16, before 6.1.175 (fixed in 6.1.175); from 6.2, before 6.6.142 (fixed in 6.6.142); from 6.7, before 6.12.92 (fixed in 6.12.92); from 6.13, before 6.18.34 (fixed in 6.18.34); …
Published 2026-07-19. Last modified 2026-09-02.