---
id: CVE-2026-64552
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  virtio-net: fix len check in receive_big()

  receive_big() bounds the device-announced length by
  (big_packets_num_skbfrags + 1) * PAGE_SIZE
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  virtio-net: fix len check in receive_big()

  receive_big() bounds the device-announced length by
  (big_packets_num_skbfrags + 1) * PAGE_SIZE.  That is still too loose:
  ad…
severity: high
cvss: 8.4
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 82f9028e83944a9eee5229cbc6fee9be1de8a62d <
    f9451d0fd5ba635dcabb49bfe456a6db734a8986
  - >-
    Linux >= 946dec89c41726b94d31147ec528b96af0be1b5a <
    38e94d63e29f4a5c6eae87ee2c02101aaa321502
  - >-
    Linux >= 82fe78065450d2d07f36a22e2b6b44955cf5ca5b <
    fbeb65154583879d556ea94cb2f15888e9470f3d
  - >-
    Linux >= 0c716703965ffc5ef4311b65cb5d84a703784717 <
    c7fc9adf4e006155f7f2aeda052fbcde25cdcc49
  - >-
    Linux >= 0c716703965ffc5ef4311b65cb5d84a703784717 <
    e6b8463b7d791f3886d7584259d6e9f06a69f12e
  - >-
    Linux >= 0c716703965ffc5ef4311b65cb5d84a703784717 <
    9e5ad06ea826322ce8c58b4a68442a96f600c3c4
  - Linux 3e9d89f2ecd3636bd4cbdfd0b2dfdaf58f9882e2
  - Linux >= 6.1.159 < 6.1.178
  - Linux >= 6.6.117 < 6.6.145
  - Linux >= 6.12.58 < 6.12.97
  - Linux >= 6.17.8 < 6.18
  - Linux 6.18
published: '2026-07-27'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T09:18:20.187'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-64552'
references:
  - url: 'https://git.kernel.org/stable/c/38e94d63e29f4a5c6eae87ee2c02101aaa321502'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/9e5ad06ea826322ce8c58b4a68442a96f600c3c4'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/c7fc9adf4e006155f7f2aeda052fbcde25cdcc49'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/e6b8463b7d791f3886d7584259d6e9f06a69f12e'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/f9451d0fd5ba635dcabb49bfe456a6db734a8986'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/fbeb65154583879d556ea94cb2f15888e9470f3d'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://cert-portal.siemens.com/productcert/html/ssa-019113.html'
    label: 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e
tags:
  - nvd
  - cve.org
epss: 0.00196
epssPercentile: 0.08201
ingestedAt: '2026-09-08T15:33:26.950Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

virtio-net: fix len check in receive_big()

receive_big() bounds the device-announced length by
(big_packets_num_skbfrags + 1) * PAGE_SIZE.  That is still too loose:
add_recvbuf_big() sets sg[1] to start at offset
sizeof(struct padded_vnet_hdr) into the first page, so the chain
actually carries hdr_len + (PAGE_SIZE - sizeof(padded_vnet_hdr)) +
big_packets_num_skbfrags * PAGE_SIZE bytes -- 20 bytes less than the
check allows for the common hdr_len == 12 case.

A malicious virtio backend can announce a len in that gap.  page_to_skb()
then walks one frag past the page chain, storing a NULL page->private
into skb_shinfo()->frags[MAX_SKB_FRAGS], which is both an out-of-bounds
write past the static frag array and a NULL frag handed up the rx path.

Bound len by the size add_recvbuf_big() actually advertised.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
