Answer in brief
CVE-2026-64552 records a High severity (CVSS 8.4) vulnerability in virtio-net: fix len check in receive_big(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic), Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (generic), Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 8.4. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic), Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (generic), Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=82f9028e83944a9eee5229cbc6fee9be1de8a62d <f9451d0fd5ba635dcabb49bfe456a6db734a8986 || >=946dec89c41726b94d31147ec528b96af0be1b5a <38e94d63e29f4a5c6eae87ee2c02101aaa321502 || >=82fe78065450d2d07f36a22e2b6b44955cf5ca5b <fbeb65154583879d556ea94cb2f15888e9470f3d || >=0c716703965ffc5ef4311b65cb5d84a703784717 <c7fc9adf4e006155f7f2aeda052fbcde25cdcc49 || >=0c716703965ffc5ef4311b65cb5d84a703784717 <e6b8463b7d791f3886d7584259d6e9f06a69f12e || >=0c716703965ffc5ef4311b65cb5d84a703784717 <9e5ad06ea826322ce8c58b4a68442a96f600c3c4 || 3e9d89f2ecd3636bd4cbdfd0b2dfdaf58f9882e2 || >=6.1.159 <6.1.178 || >=6.6.117 <6.6.145 || >=6.12.58 <6.12.97 || >=6.17.8 <6.18 | f9451d0fd5ba635dcabb49bfe456a6db734a8986, 38e94d63e29f4a5c6eae87ee2c02101aaa321502, fbeb65154583879d556ea94cb2f15888e9470f3d, c7fc9adf4e006155f7f2aeda052fbcde25cdcc49, e6b8463b7d791f3886d7584259d6e9f06a69f12e, 9e5ad06ea826322ce8c58b4a68442a96f600c3c4, 6.1.178, 6.6.145, 6.12.97, 6.18 |
| Linux/Linuxgeneric | 6.18 | Not reported |
| Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFPgeneric | >=V3.1.6 <* | * |
| Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFPgeneric | >=V3.1.6 <* | * |
| Siemens/SIPLUS S7-1500 CPU 1518-4 PN/DP MFPgeneric | >=V3.1.6 <* | * |
Published upstream
Jul 27, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 8, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: virtio-net: fix len check in receive_big() receive_big() bounds the device-announced length by (big_packets_num_skbfrags + 1) * PAGE_SIZE. That is still too loose: add_recvbuf_big() sets sg[1] to start at offset sizeof(struct padded_vnet_hdr) into the first page, so the chain actually carries hdr_len + (PAGE_SIZE - sizeof(padded_vnet_hdr)) + big_packets_num_skbfrags * PAGE_SIZE bytes -- 20 bytes less than the check allows for the common hdr_len == 12 case. A malicious virtio backend can announce a len in that gap. page_to_skb() then walks one frag past the page chain, storing a NULL page->private into skb_shinfo()->frags[MAX_SKB_FRAGS], which is both an out-of-bounds write past the static frag array and a NULL frag handed up the rx path. Bound len by the size add_recvbuf_big() actually advertised.
Quoted source text, attributed separately from HOL analysis.