Out-of-bounds read in Linux kernel - CVE-2026-64527
Published: July 27, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in hyperv_receive() and hyperv_receive_sub() in the Hyper-V DRM protocol handler when handling oversized or malformed VMBus packets. A remote attacker can send a specially crafted VMBus packet to cause a denial of service.
An error path may report a required packet length larger than the 16 KiB receive buffer, leading the code to use that length unsafely if forwarded for copying.
Affected software
Ubuntu
linux-aws (Ubuntu package)
linux-gcp-7.0 (Ubuntu package)
linux-nvidia (Ubuntu package)
linux-nvidia-bos (Ubuntu package)
How to mitigate CVE-2026-64527
linux-aws (Ubuntu package) - addressed in versions 7.0.0-1009.9, 7.0.0-1015.15
linux-gcp-7.0 (Ubuntu package) - update to 7.0.0-1011.11~24.04.1
linux-nvidia (Ubuntu package) - addressed in versions 7.0.0-1016.16, 7.0.0-1016.16~24.04.1
linux-nvidia-bos (Ubuntu package) - update to 7.0.0-2016.16
External References
- https://git.kernel.org/stable/c/049a6b474823049fe60212f25f26e4b30f44ee8f
- https://git.kernel.org/stable/c/164dc7bf17609340233c6bf4f66bb7c7008a0511
- https://git.kernel.org/stable/c/57d5d697642e05d5dd2d40660817765943dd709f
- https://git.kernel.org/stable/c/588c84b461393ff1998ac7b97b04f953f642e0df
- https://git.kernel.org/stable/c/7f87763f47a3c22fb50265a00619ef10f2394b18
- https://git.kernel.org/stable/c/c8974d96b6a5496f33dc69a3ce28a7bf5078def4
- https://git.kernel.org/stable/c/f5251226551bfec98c4705641b6f94ff1f238d91