CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-64056

criticalCVSS 9.8covered by 19 sourcesfirst seen 2026-07-19
In the Linux kernel, the following vulnerability has been resolved: net: ethernet: cortina: Make RX SKB per-port The SKB used to assemble packets from fragments in gmac_rx() is static local, but the Gemini has two ethernet ports, meaning there can be races between the ports on a bad day if a device is using both. Make the RX SKB a per-port variable and carry it over between invocations in the port struct instead. Zero the pointer once we call napi_gro_frags(), on error (after calling napi_free_frags()) or if the port is stopped. Zero it in some place where not strictly necessary just to emphasize what is going on. This was found by Sashiko during normal patch review.

CSIRTS triage

What
Multiple kernel flaws including NTFS file system out-of-bounds read, AMD processor floating point unit data exposure, and AMD Zen 2 operation cache isolation failure.
Who is affected
Systems running affected Linux kernel versions; local attackers on systems with NTFS mounted or AMD processors.
Urgency
Moderate to high — local attackers can gain privilege escalation and information disclosure; apply patches promptly.
Action
Apply kernel security updates provided by distribution maintainer.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-64056

Get an email if CVE-2026-64056 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (19)

External references

NVD record for CVE-2026-64056

CVE.org record

Embed the live status

CVE-2026-64056 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-64056 status](https://www.csirts.com/badge/CVE-2026-64056)](https://www.csirts.com/cve/CVE-2026-64056)