CVE-2026-64552: Linux

High severity, CVSS 8.4. EPSS: 0.1% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: virtio-net: fix len check in receive_big() receive_big() bounds the device-announced length by (big_packets_num_skbfrags + 1) * PAGE_SIZE. That is still too loose: add_recvbuf_big() sets sg[1] to start at offset sizeof(struct padded_vnet_hdr) into the first page, so the chain actually carries hdr_len + (PAGE_SIZE - sizeof(padded_vnet_hdr)) + big_packets_num_skbfrags * PAGE_SIZE bytes -- 20 bytes less than the check allows for the common hdr_len == 12 case. A malicious virtio backend can announce a len in that gap. page_to_skb() then walks one frag past the page chain, storing a NULL page->private into skb_shinfo()->frags[MAX_SKB_FRAGS], which is both an out-of-bounds write past the static frag array and a NULL frag handed up the rx path. Bound len by the size add_recvbuf_big() actually advertised.

Affected products

  • Linux Linux: from 6.1.159, before 6.1.178 (fixed in 6.1.178); from 6.6.117, before 6.6.145 (fixed in 6.6.145); from 6.12.58, before 6.12.97 (fixed in 6.12.97); from 6.17.8, before 6.18 (fixed in 6.18); from 6.18, before 6.18.40 (fixed in 6.18.40); from 6.19, before 7.1.5 (fixed in 7.1.5)
  • Siemens SIMATIC s7-1500 CPU 1518-4 Pn/dp Mfp: from V3.1.6
  • Siemens SIMATIC s7-1500 CPU 1518f-4 Pn/dp Mfp: from V3.1.6
  • Siemens Siplus s7-1500 CPU 1518-4 Pn/dp Mfp: from V3.1.6

Published 2026-07-27. Last modified 2026-09-08.