Junglewise Threat Intelligence

CVE-2026-64552: Linux Kernel virtio-net out-of-bounds write in receive_big

CVE-2026-64552 · Severity: info · Published 2026-07-27

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's virtio-net driver, which handles network communication in virtualized environments. A malicious virtual machine host or backend could send specially crafted network packets that exceed expected memory boundaries. This could lead to a system crash or potentially allow for unauthorized memory access, impacting the stability and security of the virtualized guest operating system.

Technical details

An out-of-bounds write vulnerability exists in the Linux kernel's virtio-net driver within the `receive_big()` function. The root cause is an insufficient boundary check on the device-announced packet length. While the code attempted to bound the length by `(big_packets_num_skbfrags + 1) * PAGE_SIZE`, it failed to account for the `sizeof(struct padded_vnet_hdr)` offset introduced in `add_recvbuf_big()`. A malicious virtio backend can provide a length that falls within this 20-byte gap, causing `page_to_skb()` to walk past the page chain and write a NULL pointer into `skb_shinfo()->frags[MAX_SKB_FRAGS]`. This results in a kernel out-of-bounds write and potential denial of service. The issue has been patched in multiple stable kernel branches.

Affected products

  • Linux Linux Kernel 6.1.159 to 6.1.178, 6.6.117 to 6.6.145, 6.12.58 to 6.12.97, 6.17.8 to 6.18

Timeline

  • 2026-06-15: disclosed: Initial patch submitted by Xiang Mei
  • 2026-07-24: patched: Commits merged into stable trees by Greg Kroah-Hartman
  • 2026-07-27: advisory: CVE-2026-64552 published

References

Related threats