Race condition in Linux kernel - CVE-2026-64056
Published: July 20, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a race condition in gmac_rx() in the cortina gemini ethernet driver when processing fragmented packets on systems using both ethernet ports. A local user can trigger concurrent packet reception to cause a denial of service.
The issue arises because a packet assembly sk_buff was shared between the two ports.
How to mitigate CVE-2026-64056
Sources
- https://git.kernel.org/stable/c/06937db21ee311ed07eba47954447245041a982d
- https://git.kernel.org/stable/c/27856d533eca3804008695f61c1e4d5ff984196b
- https://git.kernel.org/stable/c/3b249988d774dacf13b203817e971934a42243c4
- https://git.kernel.org/stable/c/67a35e7da7ef9d2f000aa758552a128324c604a0
- https://git.kernel.org/stable/c/6bba24e9ebe6f1c0b356cd471e36bdc7fa434897
- https://git.kernel.org/stable/c/72158ea185b27afae163949b0e86164cb6b64e55
- https://git.kernel.org/stable/c/b6b22824b30e48ce1df3a2e80990f4b8505deb50
- https://git.kernel.org/stable/c/cfd62907f3cdbc3b6da8f49ba907c0390018fe5e