CVE-2026-64056

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
19/07/2026
Last modified:
20/07/2026

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> net: ethernet: cortina: Make RX SKB per-port<br /> <br /> The SKB used to assemble packets from fragments in gmac_rx()<br /> is static local, but the Gemini has two ethernet ports, meaning<br /> there can be races between the ports on a bad day if a device<br /> is using both.<br /> <br /> Make the RX SKB a per-port variable and carry it over between<br /> invocations in the port struct instead.<br /> <br /> Zero the pointer once we call napi_gro_frags(), on error (after<br /> calling napi_free_frags()) or if the port is stopped.<br /> <br /> Zero it in some place where not strictly necessary just to<br /> emphasize what is going on.<br /> <br /> This was found by Sashiko during normal patch review.