CVE-2026-64055
Last modified
CVE-2026-64055 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. In the Linux kernel, the following vulnerability has been resolved: net: ethernet: cortina: Carry over frag counter The gmac_rx() NAPI poll function assembles packets in an SKB from a ring buffer. If the ring buffer gets completely emptied during a poll cycle, we exit gmac_rx(), but the packet is not yet completely assembled in the SKB, yet the fragment counter frag_nr is reset to zero on the next invocation. Solve this by making the RX fragment counter a part of the port struct, and carry it over between invocations. Reset the fragment counter only right after calling napi_gro_frags(), on error (after calling napi_free_frags()) or if stopping the port. Reset it in some place where not strictly necessary just to emphasize what is going on. This was found by Sashiko during normal patch review.. EPSS estimates a 0.51% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: net: ethernet: cortina: Carry over frag counter The gmac_rx() NAPI poll function assembles packets in an SKB from a ring buffer. If the ring buffer gets completely emptied during a poll cycle, we exit gmac_rx(), but the packet is not yet completely assembled in the SKB, yet the fragment counter frag_nr is reset to zero on the next invocation. Solve this by making the RX fragment counter a part of the port struct, and carry it over between invocations. Reset the fragment counter only right after calling napi_gro_frags(), on error (after calling napi_free_frags()) or if stopping the port. Reset it in some place where not strictly necessary just to emphasize what is going on. This was found by Sashiko during normal patch review.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 4d5ae32f5e1e13f7f36d6439ec3257993b9f5b88, < df31e3b64455293df1ea89c7da7d5c9bfbcdd253; >= 4d5ae32f5e1e13f7f36d6439ec3257993b9f5b88, < 7af1fabdee744b7995fe01b30b77dfc397657cb5; >= 4d5ae32f5e1e13f7f36d6439ec3257993b9f5b88, < 75105fcf73f1ce7d9f769aaefec6e6d6645d5ac0; >= 4d5ae32f5e1e13f7f36d6439ec3257993b9f5b88, < 78cf08b3be47c28f07008a76c932bad7cdffa9d8; >= 4d5ae32f5e1e13f7f36d6439ec3257993b9f5b88, < 7123cf481e21b54eb6adc4cb0d8dc2876aeaee41; >= 4d5ae32f5e1e13f7f36d6439ec3257993b9f5b88, < c373b34877afea61c89e0dd2e38948c624249b9b; >= 4d5ae32f5e1e13f7f36d6439ec3257993b9f5b88, < 46806096f35b8d3dfa2f321ddd77f597edcdb85f; >= 4d5ae32f5e1e13f7f36d6439ec3257993b9f5b88, < ebd8ec2b309e3a447851b456ccaf8fb39f3661e7 |
| Linux | Linux | 4.16 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-64055?
How severe is CVE-2026-64055?
How do I fix CVE-2026-64055?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-6405The Anomify AI – Anomaly Detection and Alerting plugin for W…4.3
- CVE-2026-64050In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-64051In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-64052In the Linux kernel, the following vulnerability has been re…
- CVE-2026-64053In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-64054In the Linux kernel, the following vulnerability has been re…
- CVE-2026-64056In the Linux kernel, the following vulnerability has been re…9.8
- CVE-2026-64057In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-64058In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-64059In the Linux kernel, the following vulnerability has been re…
- CVE-2026-6406The Docker CLI --use-api-socket flag bypasses Enhanced Conta…8.8
- CVE-2026-64060In the Linux kernel, the following vulnerability has been re…
Are you affected by CVE-2026-64055?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
