Back to overview

CVE-2026-64000

Description
In the Linux kernel, the following vulnerability has been resolved: net: hsr: fix potential OOB access in supervision frame handling Ensure the entire TLV header is linearized before access by adding sizeof(struct hsr_sup_tlv) to the pskb_may_pull() calls. Without this, a truncated frame could cause an out-of-bounds access.

Metadata

CVE ID
CVE-2026-64000
State
PUBLISHED
Assigner
Linux
Reserved
2026-07-19 07:54 UTC
Published
2026-07-19 14:56 UTC
Last updated
2026-07-19 14:56 UTC
Vendor / Product
Linux / Linux
Sources
cve.org  ·  NVD

Severity & Metrics

No CVSS data available.

Affected products (2)
VendorProductPlatformVersions
Linux Linux eafaa88b3eb7f28aecb222281655473431d3ef2e < 09a37dca090c55ffb1a33f52d8667f1c2367ef48, eafaa88b3eb7f28aecb222281655473431d3ef2e < a4b64f3e9c7b8259f7dd251a0313420ba7c01852, eafaa88b3eb7f28aecb222281655473431d3ef2e < 71c986c0ba45b7dc574fae27c83e7b6671556f37, eafaa88b3eb7f28aecb222281655473431d3ef2e < fbd0662f9c9a66e8cc3df3099cca8ed6d3837cc7 …
Linux Linux 5.16, 0 < 5.16, 6.1.176 ≤ 6.1.*, 6.6.143 ≤ 6.6.* …
Back to overview