Executive brief
A vulnerability was identified in the Linux kernel's Qualcomm rmnet driver, which handles data for certain mobile network interfaces. When processing incoming network traffic, the driver fails to properly verify the length of data packets before reading them. This could allow a specially crafted network frame to cause a system crash or potentially expose sensitive information from the system's memory.
Technical details
The vulnerability is a slab-out-of-bounds read located in rmnet_map_checksum_downlink_packet() within the Qualcomm rmnet driver. When ingress deaggregation is disabled, rmnet_map_ingress_handler() passes the socket buffer (skb) directly to the ingress handler without performing the length validation typically handled during deaggregation. The parser subsequently dereferences MAP headers and checksum trailers based on the packet length specified in the header without verifying it against the actual buffer length (skb->len). An attacker can exploit this by sending short, malformed frames to trigger an out-of-bounds read. The fix involves factoring out length validation into a dedicated function, rmnet_map_validate_packet_len(), and ensuring it is called on all ingress paths.
Affected products
- Linux Linux Kernel ceed73a2cf4a to ed25befc8c36f896b5878f9078faddb67fd7e2d0
Timeline
- 2026-07-24: patched: Fix committed to stable kernel tree.
- 2026-07-27: advisory: CVE-2026-64550 published.
References
- https://git.kernel.org/stable/c/00f4c366dbca16a40772c3b7ec2d8cba839e9724
- https://git.kernel.org/stable/c/14eb0c9491385d5361a292ea4974aec0e6887299
- https://git.kernel.org/stable/c/1b12612c367e4be9b0814c0468e7e687835315b4
- https://git.kernel.org/stable/c/231a8a4b76cb1b1827b3b19d7b3603642f5aaaef
- https://git.kernel.org/stable/c/3868c3244369ab709a90c9aad7534d406009b824
- https://git.kernel.org/stable/c/a54d76d176e50d2fdbd39b7231efe256170339e4
- https://git.kernel.org/stable/c/ed25befc8c36f896b5878f9078faddb67fd7e2d0