Vulnerability in Linux Kernel Affecting Qualcomm's rmnet Module
CVE-2026-64550

7.3HIGH

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
27 July 2026

What is CVE-2026-64550?

A vulnerability exists in the Linux kernel related to Qualcomm's rmnet module, where the length validation of MAP frames is bypassed during ingress parsing. When ingress deaggregation is disabled, the handling mechanism fails to check the packet length before processing, which can lead to out-of-bound reads. This issue is highlighted by a KASAN error indicating slab-out-of-bounds access, potentially allowing an attacker to exploit this flaw. It is crucial to apply patches that address this vulnerability to secure the kernel and prevent unauthorized access or data corruption.

Affected Version(s)

Linux ceed73a2cf4aff2921802aa3d21d45280677547d

Linux ceed73a2cf4aff2921802aa3d21d45280677547d

Linux ceed73a2cf4aff2921802aa3d21d45280677547d < 00f4c366dbca16a40772c3b7ec2d8cba839e9724

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.