CVE-2026-64547

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
27/07/2026
Last modified:
27/07/2026

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> net: usb: net1080: validate packet_len before pad-byte access in rx_fixup<br /> <br /> For an even packet_len, net1080_rx_fixup() reads the pad byte at<br /> skb-&gt;data[packet_len] before the skb-&gt;len != packet_len check further<br /> down, and packet_len is only bounded against NC_MAX_PACKET. A malicious<br /> NetChip 1080 device can send a short frame advertising a large even<br /> packet_len (e.g. 0x4000), so the pad-byte read lands past the end of the<br /> skb:<br /> <br /> BUG: KASAN: slab-out-of-bounds in net1080_rx_fixup<br /> Read of size 1 at addr ffff8880106c83c6 by task ksoftirqd/0/14<br /> ...<br /> net1080_rx_fixup (drivers/net/usb/net1080.c:384)<br /> usbnet_bh (drivers/net/usb/usbnet.c:1589)<br /> process_one_work (kernel/workqueue.c:3322)<br /> bh_worker (kernel/workqueue.c:3708)<br /> tasklet_action (kernel/softirq.c:965)<br /> handle_softirqs (kernel/softirq.c:622)<br /> ...<br /> <br /> Reject the frame when packet_len &gt;= skb-&gt;len before reading.

Impact