CVE-2026-64355 Details
Description
In the Linux kernel, the following vulnerability has been resolved: bpf: Reject fragmented frames in devmap Devmap broadcast redirects clone the packet for all but the last destination. For native XDP, that clone path copies only the linear xdp_frame data, while fragmented frames keep skb_shared_info in tailroom outside the linear area. Cloning such a frame leaves XDP_FLAGS_HAS_FRAGS set but without valid frag metadata, and the later free path can interpret uninitialized tail data as skb_shared_info, leading to an out-of-bounds access during frame return. Reject fragmented native XDP frames in dev_map_enqueue_clone(). Add the same restriction to the generic XDP clone path in dev_map_redirect_clone(). Generic XDP represents fragmented packets as nonlinear skbs, and rejecting them here keeps clone-based broadcast support aligned between native and generic XDP.
A vulnerability in the Linux kernel's BPF devmap handling of fragmented frames can lead to out-of-bounds access. This issue arises because devmap broadcast redirects clone packets for all destinations except the last. In native XDP, the cloning process only includes linear xdp_frame data, while fragmented frames retain skb_shared_info in tailroom outside the linear area. Cloning a fragmented frame leaves XDP_FLAGS_HAS_FRAGS set, but without valid fragment metadata. Consequently, the free path may misinterpret uninitialized tail data as skb_shared_info, causing an out-of-bounds access when returning the frame. This vulnerability affects the Linux kernel's stable versions.
Users can update to the latest patched version of the Linux kernel where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/07a4c11ee8ef4abcb39d922e9e410ae269671cdf | kernel.org | Patch |
| https://git.kernel.org/stable/c/47baddc856ae7e93a565dd9deeb797999b179466 | kernel.org | Patch |
| https://git.kernel.org/stable/c/51d07c12ca411e692c424ecdabf077f1e61a61be | kernel.org | Patch |
| https://git.kernel.org/stable/c/a9bb2d9c798cb62a4050a991c27b752770c33afe | kernel.org | Patch |
| https://git.kernel.org/stable/c/aa496720618f1a6054f1c870bf10b4f6c99bf656 | kernel.org | Patch |
| https://git.kernel.org/stable/c/bccbab36ff228e0825eb85d9b0f9b8434cd0a399 | kernel.org | Patch |
| https://git.kernel.org/stable/c/c5b4f5efcb55c1af3fe44ff712d31b7fb098a831 | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-125 | Out-of-bounds Read | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 5.14, < 5.15.212 >= 5.16, < 6.1.178 >= 6.2, < 6.6.145 >= 6.7, < 6.12.96 >= 6.13, < 6.18.39 >= 6.19, < 7.1.4 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 4, 2026 | Initial Analysis | [email protected] |
| Aug 17, 2026 | CVE Modified | kernel.org |
| Jul 27, 2026 | CVE Modified | kernel.org |
| Jul 25, 2026 | New CVE Received | kernel.org |