CVE-2026-64056 Details
Description
In the Linux kernel, the following vulnerability has been resolved: net: ethernet: cortina: Make RX SKB per-port The SKB used to assemble packets from fragments in gmac_rx() is static local, but the Gemini has two ethernet ports, meaning there can be races between the ports on a bad day if a device is using both. Make the RX SKB a per-port variable and carry it over between invocations in the port struct instead. Zero the pointer once we call napi_gro_frags(), on error (after calling napi_free_frags()) or if the port is stopped. Zero it in some place where not strictly necessary just to emphasize what is going on. This was found by Sashiko during normal patch review.
A vulnerability has been addressed in the Linux kernel's Cortina Ethernet driver for Gemini gigabit Ethernet. The issue arose because the socket buffer (SKB) used to assemble packets from fragments in the receive function was a static local variable. This design flaw could lead to race conditions when both Ethernet ports were used simultaneously. The vulnerability has been fixed by making the RX SKB a per-port variable, allowing it to be carried over between function invocations in the port structure. The patch also includes measures to reset the SKB pointer appropriately under certain conditions, such as errors or when the port is stopped.
Users can apply the available patch to address this vulnerability. The patch is included in the official Linux kernel stable tree.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/06937db21ee311ed07eba47954447245041a982d | kernel.org | Patch |
| https://git.kernel.org/stable/c/27856d533eca3804008695f61c1e4d5ff984196b | kernel.org | Patch |
| https://git.kernel.org/stable/c/3b249988d774dacf13b203817e971934a42243c4 | kernel.org | Patch |
| https://git.kernel.org/stable/c/67a35e7da7ef9d2f000aa758552a128324c604a0 | kernel.org | Patch |
| https://git.kernel.org/stable/c/6bba24e9ebe6f1c0b356cd471e36bdc7fa434897 | kernel.org | Patch |
| https://git.kernel.org/stable/c/72158ea185b27afae163949b0e86164cb6b64e55 | kernel.org | Patch |
| https://git.kernel.org/stable/c/b6b22824b30e48ce1df3a2e80990f4b8505deb50 | kernel.org | Patch |
| https://git.kernel.org/stable/c/cfd62907f3cdbc3b6da8f49ba907c0390018fe5e | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 4.16, < 5.10.258 >= 5.11, < 5.15.209 >= 5.16, < 6.1.175 >= 6.2, < 6.6.142 >= 6.7, < 6.12.92 >= 6.13, < 6.18.34 >= 6.19, < 7.0.11 7.1 rc1 7.1 rc2 7.1 rc3 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 2, 2026 | Initial Analysis | [email protected] |
| Jul 20, 2026 | CVE Modified | kernel.org |
| Jul 19, 2026 | New CVE Received | kernel.org |