{"id":"CVE-2026-64552","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nvirtio-net: fix len check in receive_big()\n\nreceive_big() bounds the device-announced length by\n(big_packets_num_skbfrags + 1) * PAGE_SIZE","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nvirtio-net: fix len check in receive_big()\n\nreceive_big() bounds the device-announced length by\n(big_packets_num_skbfrags + 1) * PAGE_SIZE.  That is still too loose:\nad…","severity":"high","cvss":8.4,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","vendor":"Linux","product":"Linux","affected":["Linux >= 82f9028e83944a9eee5229cbc6fee9be1de8a62d < f9451d0fd5ba635dcabb49bfe456a6db734a8986","Linux >= 946dec89c41726b94d31147ec528b96af0be1b5a < 38e94d63e29f4a5c6eae87ee2c02101aaa321502","Linux >= 82fe78065450d2d07f36a22e2b6b44955cf5ca5b < fbeb65154583879d556ea94cb2f15888e9470f3d","Linux >= 0c716703965ffc5ef4311b65cb5d84a703784717 < c7fc9adf4e006155f7f2aeda052fbcde25cdcc49","Linux >= 0c716703965ffc5ef4311b65cb5d84a703784717 < e6b8463b7d791f3886d7584259d6e9f06a69f12e","Linux >= 0c716703965ffc5ef4311b65cb5d84a703784717 < 9e5ad06ea826322ce8c58b4a68442a96f600c3c4","Linux 3e9d89f2ecd3636bd4cbdfd0b2dfdaf58f9882e2","Linux >= 6.1.159 < 6.1.178","Linux >= 6.6.117 < 6.6.145","Linux >= 6.12.58 < 6.12.97","Linux >= 6.17.8 < 6.18","Linux 6.18"],"published":"2026-07-27","updated":"2026-09-08","sourceUpdated":"2026-09-08T09:18:20.187","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-64552","references":[{"url":"https://git.kernel.org/stable/c/38e94d63e29f4a5c6eae87ee2c02101aaa321502","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9e5ad06ea826322ce8c58b4a68442a96f600c3c4","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c7fc9adf4e006155f7f2aeda052fbcde25cdcc49","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e6b8463b7d791f3886d7584259d6e9f06a69f12e","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f9451d0fd5ba635dcabb49bfe456a6db734a8986","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fbeb65154583879d556ea94cb2f15888e9470f3d","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://cert-portal.siemens.com/productcert/html/ssa-019113.html","label":"0b142b55-0307-4c5a-b3c9-f314f3fb7c5e"}],"tags":["nvd","cve.org"],"epss":0.00142,"epssPercentile":0.03854,"ingestedAt":"2026-09-08T15:33:26.950Z","slug":"CVE-2026-64552","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nvirtio-net: fix len check in receive_big()\n\nreceive_big() bounds the device-announced length by\n(big_packets_num_skbfrags + 1) * PAGE_SIZE.  That is still too loose:\nadd_recvbuf_big() sets sg[1] to start at offset\nsizeof(struct padded_vnet_hdr) into the first page, so the chain\nactually carries hdr_len + (PAGE_SIZE - sizeof(padded_vnet_hdr)) +\nbig_packets_num_skbfrags * PAGE_SIZE bytes -- 20 bytes less than the\ncheck allows for the common hdr_len == 12 case.\n\nA malicious virtio backend can announce a len in that gap.  page_to_skb()\nthen walks one frag past the page chain, storing a NULL page->private\ninto skb_shinfo()->frags[MAX_SKB_FRAGS], which is both an out-of-bounds\nwrite past the static frag array and a NULL frag handed up the rx path.\n\nBound len by the size add_recvbuf_big() actually advertised.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":46,"depthScoreParts":{"impact":46.2,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}