Answer in brief
CVE-2026-64505 records a Unknown severity vulnerability in usb: gadget: function: rndis: add length check for header. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2026-64505 records a Unknown severity vulnerability in usb: gadget: function: rndis: add length check for header. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=6cdee106e7571751ecc0e9f96606322f88b64a8d <200dd5092296ad4d5ae47f8445a2fb1edd1da973 || >=6cdee106e7571751ecc0e9f96606322f88b64a8d <9ffd567d7bf269824dfac06f8ab9a32fef72699b || >=6cdee106e7571751ecc0e9f96606322f88b64a8d <b73c0142e3acdc063b50c33afb7be19cdb2cd410 || >=6cdee106e7571751ecc0e9f96606322f88b64a8d <d6ef5af7d0fe1ac31e5653a77e6d775dd36bc433 || >=6cdee106e7571751ecc0e9f96606322f88b64a8d <ba2cc601e59fe68716646199a33303493513e2e3 || >=6cdee106e7571751ecc0e9f96606322f88b64a8d <7515a6d4a9e9e4838b833825882efa00e85f8901 || >=6cdee106e7571751ecc0e9f96606322f88b64a8d <9facd79028a7807879eb441d12f0e00720980aa3 || >=6cdee106e7571751ecc0e9f96606322f88b64a8d <21b5bf155435008e0fb0736795289788e63d426f | 200dd5092296ad4d5ae47f8445a2fb1edd1da973, 9ffd567d7bf269824dfac06f8ab9a32fef72699b, b73c0142e3acdc063b50c33afb7be19cdb2cd410, d6ef5af7d0fe1ac31e5653a77e6d775dd36bc433, ba2cc601e59fe68716646199a33303493513e2e3, 7515a6d4a9e9e4838b833825882efa00e85f8901, 9facd79028a7807879eb441d12f0e00720980aa3, 21b5bf155435008e0fb0736795289788e63d426f |
| Linux/Linuxgeneric | 2.6.12 | Not reported |
Published upstream
Jul 25, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 17, 2026
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: function: rndis: add length check for header Add a length check for the rndis header in rndis_rm_hdr, to ensure that MessageType, MessageLength, DataOffset, and DataLength fields are present before they are accessed.
Quoted source text, attributed separately from HOL analysis.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=6cdee106e7571751ecc0e9f96606322f88b64a8d <200dd5092296ad4d5ae47f8445a2fb1edd1da973 || >=6cdee106e7571751ecc0e9f96606322f88b64a8d <9ffd567d7bf269824dfac06f8ab9a32fef72699b || >=6cdee106e7571751ecc0e9f96606322f88b64a8d <b73c0142e3acdc063b50c33afb7be19cdb2cd410 || >=6cdee106e7571751ecc0e9f96606322f88b64a8d <d6ef5af7d0fe1ac31e5653a77e6d775dd36bc433 || >=6cdee106e7571751ecc0e9f96606322f88b64a8d <ba2cc601e59fe68716646199a33303493513e2e3 || >=6cdee106e7571751ecc0e9f96606322f88b64a8d <7515a6d4a9e9e4838b833825882efa00e85f8901 || >=6cdee106e7571751ecc0e9f96606322f88b64a8d <9facd79028a7807879eb441d12f0e00720980aa3 || >=6cdee106e7571751ecc0e9f96606322f88b64a8d <21b5bf155435008e0fb0736795289788e63d426f | 200dd5092296ad4d5ae47f8445a2fb1edd1da973, 9ffd567d7bf269824dfac06f8ab9a32fef72699b, b73c0142e3acdc063b50c33afb7be19cdb2cd410, d6ef5af7d0fe1ac31e5653a77e6d775dd36bc433, ba2cc601e59fe68716646199a33303493513e2e3, 7515a6d4a9e9e4838b833825882efa00e85f8901, 9facd79028a7807879eb441d12f0e00720980aa3, 21b5bf155435008e0fb0736795289788e63d426f |
| Linux/Linuxgeneric | 2.6.12 | Not reported |
Published upstream
Jul 25, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 17, 2026
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: function: rndis: add length check for header Add a length check for the rndis header in rndis_rm_hdr, to ensure that MessageType, MessageLength, DataOffset, and DataLength fields are present before they are accessed.
Quoted source text, attributed separately from HOL analysis.