Out-of-bounds read in Linux kernel - CVE-2026-64540

 

Out-of-bounds read in Linux kernel - CVE-2026-64540

Published: July 28, 2026


Vulnerability identifier: #VU139830
CSH Severity: Low
CVSS v4: 2.4 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-64540
CWE-ID: CWE-125
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows an attacker with physical access to disclose sensitive information.

The vulnerability exists due to an out-of-bounds read in genelink_rx_fixup() when processing device-supplied aggregated RX frames from a crafted GeneLink (GL620A) USB device. An attacker with physical access can provide a short URB with inconsistent packet length metadata to disclose sensitive information.

The issue can leak adjacent kernel heap contents to the network stack as soon as the USB network interface is up.


Affected software

Linux kernel
Debian Linux
linux (Debian package)

How to mitigate CVE-2026-64540

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3
linux (Debian package) - update to 6.12.100-1

External References

Related Security Bulletins