CVE-2026-64055·Kernel vulnerability
In the Linux kernel, the following vulnerability has been resolved: net: ethernet: cortina: Carry over frag counter The gmac_rx() NAPI poll function assembles packets in an SKB from a ring buffer. If the ring buffer gets completely emptied during a poll cycle, we exit gmac_rx(), but the packet is not yet completely assembled in the SKB, yet the fragment counter frag_nr is reset to zero on the next invocation. Solve this by making the RX fragment counter a part of the port struct, and carry it over between invocations. Reset the fragment counter only right after calling napi_gro_frags(), on error (after calling napi_free_frags()) or if stopping the port. Reset it in some place where not strictly necessary just to emphasize what is going on. This was found by Sashiko during normal patch review.
- Severity
- critical
- Software
- Kernel
- Fixed in
- 7.0.11
- Published
- 2026-07-19
Affected versions
From: 6.19
Until: 7.0.11
Fixed in: 7.0.11
How to fix this CVE
Update your Linux kernel to version 7.0.11 or later to resolve a critical packet reassembly issue in the Cortina Ethernet driver. This vulnerability affects systems running kernel versions 6.19 through 7.0.10, where improper fragment counter management can cause kernel memory corruption during network packet processing. Ensure your system's boot loader is configured to use the patched kernel version after installation.
sudo dnf update kernel kernel-headersDefensia detects this vulnerability
How to check if you are affected
- Check installed kernel version: uname -r — confirm version is 6.19 or later but below 7.0.11
- Verify Cortina Ethernet driver is in use: ethtool -i $(ip link show | grep 'state UP' | awk '{print $2}' | tr -d ':') | grep -i cortina
- Search kernel logs for packet assembly errors: dmesg | grep -i 'gmac_rx\|fragment\|skb' — look for memory corruption or data inconsistencies
- After patching, confirm kernel version updated: uname -r — should show 7.0.11 or higher, then reboot if kernel was updated
FAQ
What is CVE-2026-64055?
This is a critical vulnerability in the Linux kernel's Cortina Ethernet driver where the fragment counter used to assemble network packets is improperly reset, causing incomplete packets to corrupt kernel memory and potentially leading to system crashes or privilege escalation.
Is CVE-2026-64055 being actively exploited?
No, there are no confirmed public exploits or active exploitation campaigns reported by CISA as of this writing, though the critical severity warrants immediate patching.
What versions of Kernel are affected by CVE-2026-64055?
Linux kernel versions 6.19 through 7.0.10 are vulnerable; version 7.0.11 and later include the fix.
How do I check if my server is vulnerable to CVE-2026-64055?
Run `uname -r` to display your kernel version; if it shows 6.19–7.0.10, your system is vulnerable. Additionally, verify Cortina Ethernet hardware is present using `ethtool -i` on your active network interface.
Does Defensia detect CVE-2026-64055?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If the Linux kernel is installed on a monitored server, CVE-2026-64055 will appear in your dashboard with remediation steps.
Related Kernel CVEs
References
- https://git.kernel.org/stable/c/46806096f35b8d3dfa2f321ddd77f597edcdb85f
- https://git.kernel.org/stable/c/7123cf481e21b54eb6adc4cb0d8dc2876aeaee41
- https://git.kernel.org/stable/c/75105fcf73f1ce7d9f769aaefec6e6d6645d5ac0
- https://git.kernel.org/stable/c/78cf08b3be47c28f07008a76c932bad7cdffa9d8
- https://git.kernel.org/stable/c/7af1fabdee744b7995fe01b30b77dfc397657cb5
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2026-64055. Free for 1 server.
Get started free