CVE-2026-64055

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
19/07/2026
Last modified:
30/07/2026

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> net: ethernet: cortina: Carry over frag counter<br /> <br /> The gmac_rx() NAPI poll function assembles packets in an<br /> SKB from a ring buffer.<br /> <br /> If the ring buffer gets completely emptied during a poll cycle,<br /> we exit gmac_rx(), but the packet is not yet completely<br /> assembled in the SKB, yet the fragment counter frag_nr is<br /> reset to zero on the next invocation.<br /> <br /> Solve this by making the RX fragment counter a part of the<br /> port struct, and carry it over between invocations.<br /> <br /> Reset the fragment counter only right after calling<br /> napi_gro_frags(), on error (after calling napi_free_frags())<br /> or if stopping the port.<br /> <br /> Reset it in some place where not strictly necessary just to<br /> emphasize what is going on.<br /> <br /> This was found by Sashiko during normal patch review.