PatchSiren cyber security CVE debrief
CVE-2026-64550 Linux CVE debrief
The Linux kernel has a vulnerability in the Qualcomm rmnet driver. When ingress deaggregation is disabled, the rmnet_map_ingress_handler function passes the skb straight to __rmnet_map_ingress_handler, skipping length validation. This allows a short frame to be read out of bounds, causing a slab-out-of-bounds read. The vulnerability affects Linux kernel versions and can be used to cause a denial of service or potentially execute arbitrary code. Affected operator, platform, vulnerability-management, and security-team impact should be carefully evaluated. Linux kernel maintainers, users, and administrators of systems using the Qualcomm rmnet driver should be aware of this vulnerability and take necessary actions to fix it. The evidence for this CVE is based on a limited number of source references. Further verification is needed to confirm the affected scope and potential impact.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- HIGH 7.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-27
- Original CVE updated
- 2026-08-17
- Advisory published
- 2026-07-27
- Advisory updated
- 2026-08-17
Who should care
Linux kernel maintainers, users, and administrators of systems using the Qualcomm rmnet driver should be aware of this vulnerability and take necessary actions to fix it. The vulnerability can be used to cause a denial of service or potentially execute arbitrary code. Affected operator, platform, vulnerability-management, and security-team impact should be carefully evaluated.
Technical summary
The Qualcomm rmnet driver in the Linux kernel has a vulnerability that allows a short frame to be read out of bounds, causing a slab-out-of-bounds read. This occurs when ingress deaggregation is disabled and the rmnet_map_ingress_handler function passes the skb straight to __rmnet_map_ingress_handler, skipping length validation. The vulnerability affects Linux kernel versions and can be used to cause a denial of service or potentially execute arbitrary code. The Qualcomm rmnet driver is used in various Linux kernel versions, and the vulnerability can be exploited by sending a specially crafted packet to the affected system. The vulnerability has a high severity score and requires immediate attention from Linux kernel maintainers and users.
Defensive priority
High priority for Linux kernel maintainers and users, as this vulnerability can be used to cause a denial of service or potentially execute arbitrary code.
Recommended defensive actions
- Review and apply the provided kernel patches to fix the vulnerability
- Disable ingress deaggregation in rmnet driver configurations
- Monitor for potential out-of-bounds read attacks
- Perform inventory checks for affected Linux kernel versions
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The evidence for this CVE is based on a limited number of source references. Further verification is needed to confirm the affected scope and potential impact. Linux kernel maintainers and users should review the provided kernel patches and apply them to fix the vulnerability. The Qualcomm rmnet driver in the Linux kernel has a vulnerability that allows a short frame to be read out of bounds, causing a slab-out-of-bounds read. This occurs when ingress deaggregation is disabled and the rmnet_map_ingress_handler function passes the skb straight to __rmnet_map_ingress_handler, skipping length validation. Evidence is limited, and defenders should verify the affected scope and potential impact.
Official resources
-
CVE-2026-64550 CVE record
CVE.org
-
CVE-2026-64550 NVD detail
NVD
-
Source item URL
nvd_modified
-
Source reference
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
416baaa9-dc9f-4396-8d5f-8c081fb06d67
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-27T21:17:07.867Z and has not been modified since then.