PatchSiren cyber security CVE debrief
CVE-2026-64055 Linux CVE debrief
The Linux kernel was found to have a vulnerability in the gmac_rx() NAPI poll function, which assembles packets in an SKB from a ring buffer. If the ring buffer gets completely emptied during a poll cycle, the packet is not yet completely assembled in the SKB, and the fragment counter frag_nr is reset to zero on the next invocation. This issue was resolved by making the RX fragment counter a part of the port struct and carrying it over between invocations. The fix prevents potential denial-of-service or other issues that could arise from this vulnerability.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-19
- Original CVE updated
- 2026-07-19
- Advisory published
- 2026-07-19
- Advisory updated
- 2026-07-19
Who should care
Linux kernel users and maintainers should be aware of this vulnerability and ensure they are running a patched version of the kernel. This includes administrators and security teams responsible for Linux-based systems, as well as developers who work with the Linux kernel. They should review the patch and apply it to their systems to prevent potential exploitation.
Technical summary
The gmac_rx() NAPI poll function in the Linux kernel assembles packets in an SKB from a ring buffer. If the ring buffer is completely emptied during a poll cycle, the packet may not be fully assembled in the SKB, and the fragment counter frag_nr is reset to zero on the next invocation. To solve this, the RX fragment counter was made part of the port struct, and it is carried over between invocations. The fragment counter is reset only after calling napi_gro_frags(), on error (after calling napi_free_frags()), or when stopping the port.
Defensive priority
High priority should be given to patching this vulnerability, as it affects the Linux kernel and could potentially be used to cause denial-of-service or other issues. Linux kernel users and maintainers should take immediate action to review and apply the patch.
Recommended defensive actions
- Review and apply the patch to the Linux kernel
- Ensure that the Linux kernel is updated to a version that includes the fix
- Monitor for any potential exploitation attempts
- Verify the patch has been applied correctly
- Check for any signs of exploitation in system logs
- Consider implementing additional monitoring and detection measures
Evidence notes
The vulnerability was found by Sashiko during normal patch review. The CVE record was published on 2026-07-19T16:17:45.930Z and has not been modified since then. This issue is related to the Linux kernel, specifically in the gmac_rx() NAPI poll function, which assembles packets in an SKB from a ring buffer. If the ring buffer gets completely emptied during a poll cycle, the packet is not yet completely assembled in the SKB, and the fragment counter frag_nr is reset to zero on the next invocation. The fix involves making the RX fragment counter a part of the port struct and carrying it over between invocations.
Official resources
-
CVE-2026-64055 CVE record
CVE.org
-
CVE-2026-64055 NVD detail
NVD
-
Source item URL
nvd_modified
-
Source reference
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
416baaa9-dc9f-4396-8d5f-8c081fb06d67
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-19T16:17:45.930Z and has not been modified since then.