PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-64550 Linux CVE debrief

The Linux kernel has a vulnerability in the Qualcomm rmnet driver. When ingress deaggregation is disabled, the rmnet_map_ingress_handler function passes the skb straight to __rmnet_map_ingress_handler, skipping length validation. This allows a short frame to be read out of bounds, causing a slab-out-of-bounds read. The vulnerability affects Linux kernel versions and can be used to cause a denial of service or potentially execute arbitrary code. Affected operator, platform, vulnerability-management, and security-team impact should be carefully evaluated. Linux kernel maintainers, users, and administrators of systems using the Qualcomm rmnet driver should be aware of this vulnerability and take necessary actions to fix it. The evidence for this CVE is based on a limited number of source references. Further verification is needed to confirm the affected scope and potential impact.

Vendor
Linux
Product
Unknown
CVSS
HIGH 7.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-27
Original CVE updated
2026-08-17
Advisory published
2026-07-27
Advisory updated
2026-08-17

Who should care

Linux kernel maintainers, users, and administrators of systems using the Qualcomm rmnet driver should be aware of this vulnerability and take necessary actions to fix it. The vulnerability can be used to cause a denial of service or potentially execute arbitrary code. Affected operator, platform, vulnerability-management, and security-team impact should be carefully evaluated.

Technical summary

The Qualcomm rmnet driver in the Linux kernel has a vulnerability that allows a short frame to be read out of bounds, causing a slab-out-of-bounds read. This occurs when ingress deaggregation is disabled and the rmnet_map_ingress_handler function passes the skb straight to __rmnet_map_ingress_handler, skipping length validation. The vulnerability affects Linux kernel versions and can be used to cause a denial of service or potentially execute arbitrary code. The Qualcomm rmnet driver is used in various Linux kernel versions, and the vulnerability can be exploited by sending a specially crafted packet to the affected system. The vulnerability has a high severity score and requires immediate attention from Linux kernel maintainers and users.

Defensive priority

High priority for Linux kernel maintainers and users, as this vulnerability can be used to cause a denial of service or potentially execute arbitrary code.

Recommended defensive actions

  • Review and apply the provided kernel patches to fix the vulnerability
  • Disable ingress deaggregation in rmnet driver configurations
  • Monitor for potential out-of-bounds read attacks
  • Perform inventory checks for affected Linux kernel versions
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The evidence for this CVE is based on a limited number of source references. Further verification is needed to confirm the affected scope and potential impact. Linux kernel maintainers and users should review the provided kernel patches and apply them to fix the vulnerability. The Qualcomm rmnet driver in the Linux kernel has a vulnerability that allows a short frame to be read out of bounds, causing a slab-out-of-bounds read. This occurs when ingress deaggregation is disabled and the rmnet_map_ingress_handler function passes the skb straight to __rmnet_map_ingress_handler, skipping length validation. Evidence is limited, and defenders should verify the affected scope and potential impact.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-64550 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-64550

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-64550 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-64550

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/00f4c366dbca16a40772c3b7ec2d8cba839e9724

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/14eb0c9491385d5361a292ea4974aec0e6887299

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/1b12612c367e4be9b0814c0468e7e687835315b4

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/231a8a4b76cb1b1827b3b19d7b3603642f5aaaef

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/3868c3244369ab709a90c9aad7534d406009b824

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/a54d76d176e50d2fdbd39b7231efe256170339e4

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/ed25befc8c36f896b5878f9078faddb67fd7e2d0

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.