Memory Buffer Issue in Linux Kernel Affecting Hyper-V Integration
CVE-2026-64527
What is CVE-2026-64527?
In the Linux kernel, a vulnerability in the Hyper-V integration has been identified related to improper validation of VMBus packet sizes. The issue arises in the 'hyperv_receive_sub()' function, which incorrectly processes incoming messages without ensuring that the size of the data matches expectations. This oversight can lead to the potential exposure of residual data from previous messages, which may be misread as valid response payloads. By introducing necessary checks for packet size and ensuring that copies of messages are bounded to safe lengths, the integrity of data handling can be significantly improved. Proper error handling is crucial to prevent data leakage and improve overall system security.
Affected Version(s)
Linux 76c56a5affeba1e163b66b9d8cc192e6154466f0 < 57d5d697642e05d5dd2d40660817765943dd709f
Linux 76c56a5affeba1e163b66b9d8cc192e6154466f0
Linux 76c56a5affeba1e163b66b9d8cc192e6154466f0 < 049a6b474823049fe60212f25f26e4b30f44ee8f