Buffer Overflow in Linux Kernel Virtio Network Module
CVE-2026-64552
What is CVE-2026-64552?
A vulnerability in the Linux kernel's virtio network module allows a malicious backend to exploit a len check issue in the receive_big() function. This flaw can lead to an out-of-bounds write, potentially compromising system stability. The vulnerability arises from insufficient bounds checking of the device-announced length, specifically when handling fragmented packets. A detailed fix was implemented to ensure that the length is correctly bounded by the parameters advertised by the add_recvbuf_big() function. It’s essential for users to update their Linux kernel to mitigate this risk.
Affected Version(s)
Linux 82f9028e83944a9eee5229cbc6fee9be1de8a62d
Linux 946dec89c41726b94d31147ec528b96af0be1b5a < 38e94d63e29f4a5c6eae87ee2c02101aaa321502
Linux 82fe78065450d2d07f36a22e2b6b44955cf5ca5b