VDB

CVE-2026-64547

CVE-2026-64547 PUBLISHED CVSS 8.1 HIGH

Reported by Linux · Published July 27, 2026

In the Linux kernel, the following vulnerability has been resolved: net: usb: net1080: validate packet_len before pad-byte access in rx_fixup For an even packet_len, net1080_rx_fixup() reads the pad byte at skb->data[packet_len] before the skb->len != packet_len check further down, and packet_len is only bounded against NC_MAX_PACKET. A malicious NetChip 1080 device can send a short frame advertising a large even packet_len (e.g. 0x4000), so the pad-byte read lands past the end of the skb: BUG: KASAN: slab-out-of-bounds in net1080_rx_fixup Read of size 1 at addr ffff8880106c83c6 by task ksoftirqd/0/14 ... net1080_rx_fixup (drivers/net/usb/net1080.c:384) usbnet_bh (drivers/net/usb/usbnet.c:1589) process_one_work (kernel/workqueue.c:3322) bh_worker (kernel/workqueue.c:3708) tasklet_action (kernel/softirq.c:965) handle_softirqs (kernel/softirq.c:622) ... Reject the frame when packet_len >= skb->len before reading.

EPSS 0.28% · 19.9th percentile

Risk Scores

CVSS 3.1
8.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
EPSS Score
0.28%
19.9th percentile

Affected Products

VendorProductVersions
LinuxLinux904813cd8a0b334189da285bb05af0b18b062502, 904813cd8a0b334189da285bb05af0b18b062502, 904813cd8a0b334189da285bb05af0b18b062502
LinuxLinux2.6.14, 0, 5.10.261
LinuxLinux7.2, 904813cd8a0b334189da285bb05af0b18b062502, 904813cd8a0b334189da285bb05af0b18b062502
linuxlinux_kernel2.6.14, 2.6.14, 2.6.14

Timeline

  • Jul 27, 2026 CVE Published
  • Jul 28, 2026 Coalition ESS Score
  • Jul 28, 2026 Security Advisory
  • Aug 7, 2026 EPSS Score
  • Aug 17, 2026 CVE Updated

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›