8.4
CVE-2026-64552
- EPSS 0.14%
- Veröffentlicht 27.07.2026 20:10:40
- Zuletzt bearbeitet 17.08.2026 05:18:00
- CVE-Watchlists
- Unerledigt
virtio-net: fix len check in receive_big()
In the Linux kernel, the following vulnerability has been resolved: virtio-net: fix len check in receive_big() receive_big() bounds the device-announced length by (big_packets_num_skbfrags + 1) * PAGE_SIZE. That is still too loose: add_recvbuf_big() sets sg[1] to start at offset sizeof(struct padded_vnet_hdr) into the first page, so the chain actually carries hdr_len + (PAGE_SIZE - sizeof(padded_vnet_hdr)) + big_packets_num_skbfrags * PAGE_SIZE bytes -- 20 bytes less than the check allows for the common hdr_len == 12 case. A malicious virtio backend can announce a len in that gap. page_to_skb() then walks one frag past the page chain, storing a NULL page->private into skb_shinfo()->frags[MAX_SKB_FRAGS], which is both an out-of-bounds write past the static frag array and a NULL frag handed up the rx path. Bound len by the size add_recvbuf_big() actually advertised.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
82f9028e83944a9eee5229cbc6fee9be1de8a62d
Version <
f9451d0fd5ba635dcabb49bfe456a6db734a8986
Status
affected
Version
946dec89c41726b94d31147ec528b96af0be1b5a
Version <
38e94d63e29f4a5c6eae87ee2c02101aaa321502
Status
affected
Version
82fe78065450d2d07f36a22e2b6b44955cf5ca5b
Version <
fbeb65154583879d556ea94cb2f15888e9470f3d
Status
affected
Version
0c716703965ffc5ef4311b65cb5d84a703784717
Version <
c7fc9adf4e006155f7f2aeda052fbcde25cdcc49
Status
affected
Version
0c716703965ffc5ef4311b65cb5d84a703784717
Version <
e6b8463b7d791f3886d7584259d6e9f06a69f12e
Status
affected
Version
0c716703965ffc5ef4311b65cb5d84a703784717
Version <
9e5ad06ea826322ce8c58b4a68442a96f600c3c4
Status
affected
Version
3e9d89f2ecd3636bd4cbdfd0b2dfdaf58f9882e2
Status
affected
Version
6.1.159
Version <
6.1.178
Status
affected
Version
6.6.117
Version <
6.6.145
Status
affected
Version
6.12.58
Version <
6.12.97
Status
affected
Version
6.17.8
Version <
6.18
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
6.18
Status
affected
Version
0
Version <
6.18
Status
unaffected
Version <=
6.1.*
Version
6.1.178
Status
unaffected
Version <=
6.6.*
Version
6.6.145
Status
unaffected
Version <=
6.12.*
Version
6.12.97
Status
unaffected
Version <=
6.18.*
Version
6.18.40
Status
unaffected
Version <=
7.1.*
Version
7.1.5
Status
unaffected
Version <=
*
Version
7.2
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.14% | 0.041 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | 8.4 | 2.5 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
https://git.kernel.org/stable/c/f9451d0fd5ba635dcabb49bfe456a6db734a8986
https://git.kernel.org/stable/c/38e94d63e29f4a5c6eae87ee2c02101aaa321502
https://git.kernel.org/stable/c/fbeb65154583879d556ea94cb2f15888e9470f3d
https://git.kernel.org/stable/c/c7fc9adf4e006155f7f2aeda052fbcde25cdcc49
https://git.kernel.org/stable/c/e6b8463b7d791f3886d7584259d6e9f06a69f12e
https://git.kernel.org/stable/c/9e5ad06ea826322ce8c58b4a68442a96f600c3c4