Out-of-bounds read in Linux kernel - CVE-2026-64550
Published: July 28, 2026
Vulnerability details
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in rmnet_map_ingress_handler() and __rmnet_map_ingress_handler() when processing a crafted short MAP frame on the no-aggregation ingress path. A local user can send a specially crafted frame to disclose sensitive information.
The issue occurs when ingress deaggregation is disabled, causing packet parsing to use the on-wire packet length without verifying skb->len first.
Affected software
Debian Linux
openEuler
kernel
bpftool
bpftool-debuginfo
kernel-debuginfo
kernel-debugsource
kernel-devel
kernel-headers
kernel-source
kernel-tools
kernel-tools-debuginfo
kernel-tools-devel
perf
perf-debuginfo
python3-perf
python3-perf-debuginfo
linux (Debian package)
How to mitigate CVE-2026-64550
kernel - update to 5.10.0-329.0.0.230
bpftool - update to 5.10.0-329.0.0.230
bpftool-debuginfo - update to 5.10.0-329.0.0.230
kernel-debuginfo - update to 5.10.0-329.0.0.230
kernel-debugsource - update to 5.10.0-329.0.0.230
kernel-devel - update to 5.10.0-329.0.0.230
kernel-headers - update to 5.10.0-329.0.0.230
kernel-source - update to 5.10.0-329.0.0.230
kernel-tools - update to 5.10.0-329.0.0.230
kernel-tools-debuginfo - update to 5.10.0-329.0.0.230
kernel-tools-devel - update to 5.10.0-329.0.0.230
perf - update to 5.10.0-329.0.0.230
perf-debuginfo - update to 5.10.0-329.0.0.230
python3-perf - update to 5.10.0-329.0.0.230
python3-perf-debuginfo - update to 5.10.0-329.0.0.230
linux (Debian package) - update to 6.12.100-1
External References
- https://git.kernel.org/stable/c/00f4c366dbca16a40772c3b7ec2d8cba839e9724
- https://git.kernel.org/stable/c/14eb0c9491385d5361a292ea4974aec0e6887299
- https://git.kernel.org/stable/c/1b12612c367e4be9b0814c0468e7e687835315b4
- https://git.kernel.org/stable/c/231a8a4b76cb1b1827b3b19d7b3603642f5aaaef
- https://git.kernel.org/stable/c/3868c3244369ab709a90c9aad7534d406009b824
- https://git.kernel.org/stable/c/a54d76d176e50d2fdbd39b7231efe256170339e4
- https://git.kernel.org/stable/c/ed25befc8c36f896b5878f9078faddb67fd7e2d0
- https://git.kernel.org/stable/c/f0f1887a9e30712a1df03e152dce6fb91344b1f3