Buffer Overflow in Linux Kernel Virtio Network Module
CVE-2026-64552

8.4HIGH

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
27 July 2026

What is CVE-2026-64552?

A vulnerability in the Linux kernel's virtio network module allows a malicious backend to exploit a len check issue in the receive_big() function. This flaw can lead to an out-of-bounds write, potentially compromising system stability. The vulnerability arises from insufficient bounds checking of the device-announced length, specifically when handling fragmented packets. A detailed fix was implemented to ensure that the length is correctly bounded by the parameters advertised by the add_recvbuf_big() function. It’s essential for users to update their Linux kernel to mitigate this risk.

Affected Version(s)

Linux 82f9028e83944a9eee5229cbc6fee9be1de8a62d

Linux 946dec89c41726b94d31147ec528b96af0be1b5a < 38e94d63e29f4a5c6eae87ee2c02101aaa321502

Linux 82fe78065450d2d07f36a22e2b6b44955cf5ca5b

References

CVSS V3.1

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.