Out-of-bounds read in Linux kernel - CVE-2026-64550
Published: July 28, 2026
Vulnerability details
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in rmnet_map_ingress_handler() and __rmnet_map_ingress_handler() when processing a crafted short MAP frame on the no-aggregation ingress path. A local user can send a specially crafted frame to disclose sensitive information.
The issue occurs when ingress deaggregation is disabled, causing packet parsing to use the on-wire packet length without verifying skb->len first.
Affected software
Debian Linux
linux (Debian package)
How to mitigate CVE-2026-64550
linux (Debian package) - update to 6.12.100-1
External References
- https://git.kernel.org/stable/c/00f4c366dbca16a40772c3b7ec2d8cba839e9724
- https://git.kernel.org/stable/c/14eb0c9491385d5361a292ea4974aec0e6887299
- https://git.kernel.org/stable/c/1b12612c367e4be9b0814c0468e7e687835315b4
- https://git.kernel.org/stable/c/231a8a4b76cb1b1827b3b19d7b3603642f5aaaef
- https://git.kernel.org/stable/c/3868c3244369ab709a90c9aad7534d406009b824
- https://git.kernel.org/stable/c/a54d76d176e50d2fdbd39b7231efe256170339e4
- https://git.kernel.org/stable/c/ed25befc8c36f896b5878f9078faddb67fd7e2d0
- https://git.kernel.org/stable/c/f0f1887a9e30712a1df03e152dce6fb91344b1f3