CVE-2026-64056·Kernel vulnerability
In the Linux kernel, the following vulnerability has been resolved: net: ethernet: cortina: Make RX SKB per-port The SKB used to assemble packets from fragments in gmac_rx() is static local, but the Gemini has two ethernet ports, meaning there can be races between the ports on a bad day if a device is using both. Make the RX SKB a per-port variable and carry it over between invocations in the port struct instead. Zero the pointer once we call napi_gro_frags(), on error (after calling napi_free_frags()) or if the port is stopped. Zero it in some place where not strictly necessary just to emphasize what is going on. This was found by Sashiko during normal patch review.
- Severity
- critical
- Software
- Kernel
- Fixed in
- 7.0.11
- Published
- 2026-07-19
Affected versions
From: 6.19
Until: 7.0.11
Fixed in: 7.0.11
How to fix this CVE
Update your Linux kernel to version 7.0.11 or later to resolve a critical race condition affecting dual-port Ethernet controllers on Gemini systems. This vulnerability allows concurrent packet assembly operations across multiple ports to interfere with each other, potentially causing memory corruption or denial of service. Apply the kernel update immediately and reboot your system to ensure the fix is active.
sudo dnf update kernel kernel-develDefensia detects this vulnerability
How to check if you are affected
- Step 1: Check your kernel version with 'uname -r' and verify it is 7.0.11 or later
- Step 2: Confirm if your system uses Cortina Gemini ethernet controllers by running 'lspci -k | grep -i cortina' or checking dmesg for gmac references
- Step 3: Search kernel logs for SKB allocation failures or memory corruption patterns with 'journalctl -xe | grep -i "skb\|memory\|corruption"'
- Step 4: After patching, reboot the system and verify the new kernel is loaded with 'uname -r', then test dual-port ethernet connectivity if applicable
FAQ
What is CVE-2026-64056?
This is a critical race condition in the Cortina Gemini ethernet driver where a shared static buffer used for packet reassembly could be accessed simultaneously by multiple network ports, leading to data corruption, kernel crashes, or potential privilege escalation.
Is CVE-2026-64056 being actively exploited?
No, there are currently no known active exploits or public proof-of-concept code available for this vulnerability, though the critical CVSS score warrants immediate patching.
What versions of Kernel are affected by CVE-2026-64056?
Kernel versions 6.19 through 7.0.10 are vulnerable; version 7.0.11 and later contain the fix.
How do I check if my server is vulnerable to CVE-2026-64056?
Run 'uname -r' and compare the output against 7.0.11—if your version is lower and your hardware uses Cortina Gemini controllers, you are vulnerable.
Does Defensia detect CVE-2026-64056?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If Kernel is installed on a monitored server, CVE-2026-64056 will appear in your dashboard with remediation steps.
Related Kernel CVEs
References
- https://git.kernel.org/stable/c/06937db21ee311ed07eba47954447245041a982d
- https://git.kernel.org/stable/c/27856d533eca3804008695f61c1e4d5ff984196b
- https://git.kernel.org/stable/c/3b249988d774dacf13b203817e971934a42243c4
- https://git.kernel.org/stable/c/67a35e7da7ef9d2f000aa758552a128324c604a0
- https://git.kernel.org/stable/c/6bba24e9ebe6f1c0b356cd471e36bdc7fa434897
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2026-64056. Free for 1 server.
Get started free