SEPTEMBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-64055

CRITICAL · CVSS 9.8 EPSS 0.51%

Source: NVD + CISA KEV + EPSS · Published 2026-07-19 · Last synced 2026-08-18

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's handling of Ethernet packet assembly in the gmac_rx() NAPI poll function, where the fragment counter can be improperly reset if the ring buffer is emptied during a poll cycle. This flaw could lead to potential packet loss or corruption, impacting network stability and performance. Organizations utilizing Linux-based systems, particularly those relying on Ethernet networking, should prioritize addressing this critical vulnerability to mitigate risks associated with data integrity and network reliability.

CVE
CVE-2026-64055
Severity
CRITICAL
CVSS
9.8
EPSS
0.51%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: net: ethernet: cortina: Carry over frag counter The gmac_rx() NAPI poll function assembles packets in an SKB from a ring buffer. If the ring buffer gets completely emptied during a poll cycle, we exit gmac_rx(), but the packet is not yet completely assembled in the SKB, yet the fragment counter frag_nr is reset to zero on the next invocation. Solve this by making the RX fragment counter a part of the port struct, and carry it over between invocations. Reset the fragment counter only right after calling napi_gro_frags(), on error (after calling napi_free_frags()) or if stopping the port. Reset it in some place where not strictly necessary just to emphasize what is going on. This was found by Sashiko during normal patch review.