CRITICALVulnerability
CVE-2026-64056
In the Linux kernel, the following vulnerability has been resolved: net: ethernet: cortina: Make RX SKB per-port The SKB used to assemble packets from fragments in gmac_rx() is static local, but the Gemini has two ethernet ports, meaning there can be races between the ports on a bad day if a device is using both. Make the RX SKB a per-port variable and carry it over between invocations in the port struct instead. Zero the pointer once we call napi_gro_frags(), on error (after calling napi_free_frags()) or if the port is stopped. Zero it in some place where not strictly necessary just to emphasize what is going on. This was found by Sashiko during normal patch review.
Properties
- severity
- CRITICAL
- score
- 9.8
- epss_score
- 0.00552
- cve_id
- CVE-2026-64056
- vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- published_at
- 2026-07-19T16:17:46.057
- last_modified
- 2026-09-02T21:13:22.933
- epss_percentile
- 0.44002
Related Entities (6)
ENRICHED_BY (1)
→[Source]FIRST EPSS
AFFECTS_PRODUCT (4)
→[Product]
→[Product]
→[Product]
→[Product]
DESCRIBED_BY (1)
→[Source]NVD
Explore deeper with Ninja Signal's threat intelligence graph