CVE-2026-64355·Kernel vulnerability
In the Linux kernel, the following vulnerability has been resolved: bpf: Reject fragmented frames in devmap Devmap broadcast redirects clone the packet for all but the last destination. For native XDP, that clone path copies only the linear xdp_frame data, while fragmented frames keep skb_shared_info in tailroom outside the linear area. Cloning such a frame leaves XDP_FLAGS_HAS_FRAGS set but without valid frag metadata, and the later free path can interpret uninitialized tail data as skb_shared_info, leading to an out-of-bounds access during frame return. Reject fragmented native XDP frames in dev_map_enqueue_clone(). Add the same restriction to the generic XDP clone path in dev_map_redirect_clone(). Generic XDP represents fragmented packets as nonlinear skbs, and rejecting them here keeps clone-based broadcast support aligned between native and generic XDP.
- Severity
- critical
- Software
- Kernel
- Fixed in
- 7.1.4
- Published
- 2026-07-25
Affected versions
From: 6.19
Until: 7.1.4
Fixed in: 7.1.4
How to fix this CVE
Update your Linux kernel to version 7.1.4 or later to patch the memory safety issue in eBPF devmap packet cloning. This vulnerability affects packet forwarding in XDP programs when fragmented frames are cloned for broadcast operations. Apply the kernel update and reboot your system to eliminate the risk of out-of-bounds memory access.
sudo dnf update kernel kernel-devel kernel-headersDefensia detects this vulnerability
How to check if you are affected
- Run 'uname -r' to verify your current kernel version; versions 6.19.x through 7.1.3 are vulnerable
- Check if XDP programs are loaded on your system with 'ip link show' and inspect for any devmap redirect or broadcast operations in active eBPF programs
- Search kernel logs for memory access errors: 'dmesg | grep -i "out of bounds\|segfault\|BUG"' which may indicate exploitation attempts
- Confirm the fix by upgrading to kernel 7.1.4+ and verifying with 'uname -r' after reboot, then validate eBPF programs reload without errors
FAQ
What is CVE-2026-64355?
This vulnerability affects Linux kernel eBPF packet processing, specifically the devmap redirect mechanism used in XDP programs. When fragmented packets are cloned for broadcast operations, incomplete metadata leaves the frame in an invalid state, allowing uninitialized memory to be interpreted as packet structures during cleanup, causing an out-of-bounds read.
Is CVE-2026-64355 being actively exploited?
No, this vulnerability is not currently listed in CISA's Known Exploited Vulnerabilities catalog and no public exploits are available, though the memory safety issue makes it a valuable target for determined attackers.
What versions of Kernel are affected by CVE-2026-64355?
Linux kernel versions 6.19 through 7.1.3 are vulnerable; version 7.1.4 and later include the fix.
How do I check if my server is vulnerable to CVE-2026-64355?
Run 'uname -r' and compare your version against the vulnerable range (6.19-7.1.3). Additionally, confirm XDP is in use with 'ethtool -i <interface>' or 'ip link show' for BPF programs, as the vulnerability only affects systems actively using XDP devmap redirects.
Does Defensia detect CVE-2026-64355?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If Kernel is installed on a monitored server, CVE-2026-64355 will appear in your dashboard with remediation steps.
Related Kernel CVEs
References
- https://git.kernel.org/stable/c/07a4c11ee8ef4abcb39d922e9e410ae269671cdf
- https://git.kernel.org/stable/c/47baddc856ae7e93a565dd9deeb797999b179466
- https://git.kernel.org/stable/c/51d07c12ca411e692c424ecdabf077f1e61a61be
- https://git.kernel.org/stable/c/a9bb2d9c798cb62a4050a991c27b752770c33afe
- https://git.kernel.org/stable/c/aa496720618f1a6054f1c870bf10b4f6c99bf656
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2026-64355. Free for 1 server.
Get started free