CVE-2026-64056
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
19/07/2026
Last modified:
20/07/2026
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
net: ethernet: cortina: Make RX SKB per-port<br />
<br />
The SKB used to assemble packets from fragments in gmac_rx()<br />
is static local, but the Gemini has two ethernet ports, meaning<br />
there can be races between the ports on a bad day if a device<br />
is using both.<br />
<br />
Make the RX SKB a per-port variable and carry it over between<br />
invocations in the port struct instead.<br />
<br />
Zero the pointer once we call napi_gro_frags(), on error (after<br />
calling napi_free_frags()) or if the port is stopped.<br />
<br />
Zero it in some place where not strictly necessary just to<br />
emphasize what is going on.<br />
<br />
This was found by Sashiko during normal patch review.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/06937db21ee311ed07eba47954447245041a982d
- https://git.kernel.org/stable/c/27856d533eca3804008695f61c1e4d5ff984196b
- https://git.kernel.org/stable/c/3b249988d774dacf13b203817e971934a42243c4
- https://git.kernel.org/stable/c/67a35e7da7ef9d2f000aa758552a128324c604a0
- https://git.kernel.org/stable/c/6bba24e9ebe6f1c0b356cd471e36bdc7fa434897
- https://git.kernel.org/stable/c/72158ea185b27afae163949b0e86164cb6b64e55
- https://git.kernel.org/stable/c/b6b22824b30e48ce1df3a2e80990f4b8505deb50
- https://git.kernel.org/stable/c/cfd62907f3cdbc3b6da8f49ba907c0390018fe5e



