Answer in brief
CVE-2026-64552 records a Unknown severity vulnerability in virtio-net: fix len check in receive_big(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=82f9028e83944a9eee5229cbc6fee9be1de8a62d <f9451d0fd5ba635dcabb49bfe456a6db734a8986 || >=946dec89c41726b94d31147ec528b96af0be1b5a <38e94d63e29f4a5c6eae87ee2c02101aaa321502 || >=82fe78065450d2d07f36a22e2b6b44955cf5ca5b <fbeb65154583879d556ea94cb2f15888e9470f3d || >=0c716703965ffc5ef4311b65cb5d84a703784717 <c7fc9adf4e006155f7f2aeda052fbcde25cdcc49 || >=0c716703965ffc5ef4311b65cb5d84a703784717 <e6b8463b7d791f3886d7584259d6e9f06a69f12e || >=0c716703965ffc5ef4311b65cb5d84a703784717 <9e5ad06ea826322ce8c58b4a68442a96f600c3c4 || 3e9d89f2ecd3636bd4cbdfd0b2dfdaf58f9882e2 || >=6.1.159 <6.1.178 || >=6.6.117 <6.6.145 || >=6.12.58 <6.12.97 || >=6.17.8 <6.18 | f9451d0fd5ba635dcabb49bfe456a6db734a8986, 38e94d63e29f4a5c6eae87ee2c02101aaa321502, fbeb65154583879d556ea94cb2f15888e9470f3d, c7fc9adf4e006155f7f2aeda052fbcde25cdcc49, e6b8463b7d791f3886d7584259d6e9f06a69f12e, 9e5ad06ea826322ce8c58b4a68442a96f600c3c4, 6.1.178, 6.6.145, 6.12.97, 6.18 |
| Linux/Linuxgeneric | 6.18 | Not reported |
Published upstream
Jul 27, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: virtio-net: fix len check in receive_big() receive_big() bounds the device-announced length by (big_packets_num_skbfrags + 1) * PAGE_SIZE. That is still too loose: add_recvbuf_big() sets sg[1] to start at offset sizeof(struct padded_vnet_hdr) into the first page, so the chain actually carries hdr_len + (PAGE_SIZE - sizeof(padded_vnet_hdr)) + big_packets_num_skbfrags * PAGE_SIZE bytes -- 20 bytes less than the check allows for the common hdr_len == 12 case. A malicious virtio backend can announce a len in that gap. page_to_skb() then walks one frag past the page chain, storing a NULL page->private into skb_shinfo()->frags[MAX_SKB_FRAGS], which is both an out-of-bounds write past the static frag array and a NULL frag handed up the rx path. Bound len by the size add_recvbuf_big() actually advertised.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2026-64552 records a Unknown severity vulnerability in virtio-net: fix len check in receive_big(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=82f9028e83944a9eee5229cbc6fee9be1de8a62d <f9451d0fd5ba635dcabb49bfe456a6db734a8986 || >=946dec89c41726b94d31147ec528b96af0be1b5a <38e94d63e29f4a5c6eae87ee2c02101aaa321502 || >=82fe78065450d2d07f36a22e2b6b44955cf5ca5b <fbeb65154583879d556ea94cb2f15888e9470f3d || >=0c716703965ffc5ef4311b65cb5d84a703784717 <c7fc9adf4e006155f7f2aeda052fbcde25cdcc49 || >=0c716703965ffc5ef4311b65cb5d84a703784717 <e6b8463b7d791f3886d7584259d6e9f06a69f12e || >=0c716703965ffc5ef4311b65cb5d84a703784717 <9e5ad06ea826322ce8c58b4a68442a96f600c3c4 || 3e9d89f2ecd3636bd4cbdfd0b2dfdaf58f9882e2 || >=6.1.159 <6.1.178 || >=6.6.117 <6.6.145 || >=6.12.58 <6.12.97 || >=6.17.8 <6.18 | f9451d0fd5ba635dcabb49bfe456a6db734a8986, 38e94d63e29f4a5c6eae87ee2c02101aaa321502, fbeb65154583879d556ea94cb2f15888e9470f3d, c7fc9adf4e006155f7f2aeda052fbcde25cdcc49, e6b8463b7d791f3886d7584259d6e9f06a69f12e, 9e5ad06ea826322ce8c58b4a68442a96f600c3c4, 6.1.178, 6.6.145, 6.12.97, 6.18 |
| Linux/Linuxgeneric | 6.18 | Not reported |
Published upstream
Jul 27, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: virtio-net: fix len check in receive_big() receive_big() bounds the device-announced length by (big_packets_num_skbfrags + 1) * PAGE_SIZE. That is still too loose: add_recvbuf_big() sets sg[1] to start at offset sizeof(struct padded_vnet_hdr) into the first page, so the chain actually carries hdr_len + (PAGE_SIZE - sizeof(padded_vnet_hdr)) + big_packets_num_skbfrags * PAGE_SIZE bytes -- 20 bytes less than the check allows for the common hdr_len == 12 case. A malicious virtio backend can announce a len in that gap. page_to_skb() then walks one frag past the page chain, storing a NULL page->private into skb_shinfo()->frags[MAX_SKB_FRAGS], which is both an out-of-bounds write past the static frag array and a NULL frag handed up the rx path. Bound len by the size add_recvbuf_big() actually advertised.
Quoted source text, attributed separately from HOL analysis.