PatchSiren cyber security CVE debrief
CVE-2026-64550 Linux CVE debrief
The Linux kernel has a vulnerability in the Qualcomm rmnet driver. When ingress deaggregation is disabled, the rmnet_map_ingress_handler function passes the skb straight to __rmnet_map_ingress_handler, skipping length validation. This allows a short frame to be read out of bounds, causing a slab-out-of-bounds read. The vulnerability affects Linux kernel versions and can be used to cause a denial of service or potentially execute arbitrary code. Affected operator, platform, vulnerability-management, and security-team impact should be carefully evaluated. Linux kernel maintainers, users, and administrators of systems using the Qualcomm rmnet driver should be aware of this vulnerability and take necessary actions to fix it. The evidence for this CVE is based on a limited number of source references. Further verification is needed to confirm the affected scope and potential impact.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- HIGH 7.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-27
- Original CVE updated
- 2026-08-17
- Advisory published
- 2026-07-27
- Advisory updated
- 2026-08-17
Who should care
Linux kernel maintainers, users, and administrators of systems using the Qualcomm rmnet driver should be aware of this vulnerability and take necessary actions to fix it. The vulnerability can be used to cause a denial of service or potentially execute arbitrary code. Affected operator, platform, vulnerability-management, and security-team impact should be carefully evaluated.
Technical summary
The Qualcomm rmnet driver in the Linux kernel has a vulnerability that allows a short frame to be read out of bounds, causing a slab-out-of-bounds read. This occurs when ingress deaggregation is disabled and the rmnet_map_ingress_handler function passes the skb straight to __rmnet_map_ingress_handler, skipping length validation. The vulnerability affects Linux kernel versions and can be used to cause a denial of service or potentially execute arbitrary code. The Qualcomm rmnet driver is used in various Linux kernel versions, and the vulnerability can be exploited by sending a specially crafted packet to the affected system. The vulnerability has a high severity score and requires immediate attention from Linux kernel maintainers and users.
Defensive priority
High priority for Linux kernel maintainers and users, as this vulnerability can be used to cause a denial of service or potentially execute arbitrary code.
Recommended defensive actions
- Review and apply the provided kernel patches to fix the vulnerability
- Disable ingress deaggregation in rmnet driver configurations
- Monitor for potential out-of-bounds read attacks
- Perform inventory checks for affected Linux kernel versions
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The evidence for this CVE is based on a limited number of source references. Further verification is needed to confirm the affected scope and potential impact. Linux kernel maintainers and users should review the provided kernel patches and apply them to fix the vulnerability. The Qualcomm rmnet driver in the Linux kernel has a vulnerability that allows a short frame to be read out of bounds, causing a slab-out-of-bounds read. This occurs when ingress deaggregation is disabled and the rmnet_map_ingress_handler function passes the skb straight to __rmnet_map_ingress_handler, skipping length validation. Evidence is limited, and defenders should verify the affected scope and potential impact.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-64550 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-64550
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-64550 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-64550
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/00f4c366dbca16a40772c3b7ec2d8cba839e9724
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/14eb0c9491385d5361a292ea4974aec0e6887299
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/1b12612c367e4be9b0814c0468e7e687835315b4
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/231a8a4b76cb1b1827b3b19d7b3603642f5aaaef
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/3868c3244369ab709a90c9aad7534d406009b824
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/a54d76d176e50d2fdbd39b7231efe256170339e4
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/ed25befc8c36f896b5878f9078faddb67fd7e2d0
416baaa9-dc9f-4396-8d5f-8c081fb06d67
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.