CVE-2026-64056
In the Linux kernel, the following vulnerability has been resolved:
net: ethernet: cortina: Make RX SKB per-port
The SKB used to assemble packets from fragments in gmac_rx()
is static local, but the Gemini has two ethernet ports, meaning
there can be races between the ports on a bad day if a device
is using both.
Make the RX SKB a per-port variable and carry it over between
invocations in the port struct instead.
Zero the pointer once we call napi_gro_frags(), on error (after
calling napi_free_frags()) or if the port is stopped.
Zero it in some place where not strictly necessary just to
emphasize what is going on.
This was found by Sashiko during normal patch review.
CSIRTS triage
- What
- Multiple kernel flaws including NTFS file system out-of-bounds read, AMD processor floating point unit data exposure, and AMD Zen 2 operation cache isolation failure.
- Who is affected
- Systems running affected Linux kernel versions; local attackers on systems with NTFS mounted or AMD processors.
- Urgency
- Moderate to high — local attackers can gain privilege escalation and information disclosure; apply patches promptly.
- Action
- Apply kernel security updates provided by distribution maintainer.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2026-64056
Get an email if CVE-2026-64056 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.55% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 44% of all EPSS-scored CVEs.
Advisory coverage (19)
- unknownUSN-8729-1: Linux kernel vulnerabilitiesubuntu · 2026-09-07
- unknownexploitedUSN-8728-1: Linux kernel (GCP) vulnerabilitiesubuntu · 2026-09-07
- unknownUSN-8668-1: Linux kernel (GCP) vulnerabilitiesubuntu · 2026-08-21
- unknownUSN-8664-1: Linux kernel (NVIDIA BaseOS) vulnerabilitiesubuntu · 2026-08-20
- unknownUSN-8663-1: Linux kernel (NVIDIA) vulnerabilitiesubuntu · 2026-08-20
- unknownUSN-8620-4: Linux kernel (Intel IoTG) vulnerabilitiesubuntu · 2026-07-31
- unknownUSN-8620-3: Linux kernel (Intel IoTG) vulnerabilitiesubuntu · 2026-07-31
- unknownUSN-8620-2: Linux kernel (Azure FIPS) vulnerabilitiesubuntu · 2026-07-29
- highUSN-8620-1: Linux kernel vulnerabilitiesubuntu · 2026-07-28
- highUSN-8618-1: Linux kernel vulnerabilitiesubuntu · 2026-07-28
- highUSN-8610-1: Linux kernel (Azure CVM) vulnerabilitiesubuntu · 2026-07-24
- highUSN-8575-3: Linux kernel vulnerabilitiesubuntu · 2026-07-24
- highUSN-8603-1: Linux kernel (Azure) vulnerabilitiesubuntu · 2026-07-24
- highUSN-8576-2: Linux kernel (NVIDIA Tegra) vulnerabilitiesubuntu · 2026-07-23
- highUSN-8575-2: Linux kernel vulnerabilitiesubuntu · 2026-07-23
- highUSN-8593-1: Linux kernel vulnerabilitiesubuntu · 2026-07-23
- highUSN-8576-1: Linux kernel (NVIDIA Tegra) vulnerabilitiesubuntu · 2026-07-21
- highUSN-8575-1: Linux kernel vulnerabilitiesubuntu · 2026-07-21
- criticalCVE-2026-64056: In the Linux kernel, the following vulnerability has been resolved: net: ethernet: cortina: Ma…nvd · 2026-07-19
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-64056)