CVE-2026-64355: bpf: Reject fragmented frames in devmap

Published Jul 25, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

bpf: Reject fragmented frames in devmap

Devmap broadcast redirects clone the packet for all but the last destination.

For native XDP, that clone path copies only the linear xdpframe data, while fragmented frames keep skbsharedinfo in tailroom outside the linear area. Cloning such a frame leaves XDPFLAGSHASFRAGS set but without valid frag metadata, and the later free path can interpret uninitialized tail data as skbsharedinfo, leading to an out-of-bounds access during frame return.

Reject fragmented native XDP frames in devmapenqueueclone().

Add the same restriction to the generic XDP clone path in devmapredirectclone(). Generic XDP represents fragmented packets as nonlinear skbs, and rejecting them here keeps clone-based broadcast support aligned between native and generic XDP.

Affected Software

7 affected components
Linux Linux kernel
Linux Linux kernel>=5.14<5.15.212
Linux Linux kernel>=5.16<6.1.178
Linux Linux kernel>=6.2<6.6.145
Linux Linux kernel>=6.7<6.12.96
Linux Linux kernel>=6.13<6.18.39
Linux Linux kernel>=6.19<7.1.4

Event History

Jul 25, 2026
CVE Published
via MITRE·08:50 AM
Data Sourced
via MITRE·08:50 AM
DescriptionSeverity
Data Sourced
via NVD·10:17 AM
RemedyDescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2026-64355?

CVE-2026-64355 has a critical severity rating of 9.8 according to the CVSS 3.1 score.

2

What impact does CVE-2026-64355 have on affected systems?

CVE-2026-64355 can lead to potential data integrity issues as it allows for fragmented network frames to be processed incorrectly.

3

How do I fix CVE-2026-64355?

To fix CVE-2026-64355, users should update their Linux kernel to the latest version where the vulnerability has been addressed.

4

Which versions of the Linux kernel are affected by CVE-2026-64355?

CVE-2026-64355 affects all versions of the Linux kernel prior to the patched updates provided after the vulnerability was reported.

5

What does CVE-2026-64355 mean for network security?

CVE-2026-64355 poses a significant risk to network security as it can allow attackers to manipulate packet handling via fragmented frames.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203