Back to overview

CVE-2026-64018

Description
In the Linux kernel, the following vulnerability has been resolved: net: mana: validate rx_req_idx to prevent out-of-bounds array access In mana_hwc_rx_event_handler(), rx_req_idx is derived from sge->address in DMA-coherent memory. In Confidential VMs (SEV-SNP/TDX), this memory is shared unencrypted and HW can modify WQE contents at any time. No bounds check exists on rx_req_idx, which can lead to an out-of-bounds access into reqs[]. Add bounds check on rx_req_idx in mana_hwc_rx_event_handler() before using it to index the reqs[] array.

Metadata

CVE ID
CVE-2026-64018
State
PUBLISHED
Assigner
Linux
Reserved
2026-07-19 07:54 UTC
Published
2026-07-19 15:39 UTC
Last updated
2026-07-19 15:39 UTC
Vendor / Product
Linux / Linux
Sources
cve.org  ·  NVD

Severity & Metrics

No CVSS data available.

Affected products (2)
VendorProductPlatformVersions
Linux Linux ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f < 5ddc715324badd7f2641bc177db1d027b402adae, ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f < ff1d5af207bcea857d45fe81505f1bc4b29eaef0, ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f < 01f7f893d5e1baae995beeb86cd0f3e6bb2a3b01, ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f < 763a372d344fb12fae566d36ddb46e92454ad58c …
Linux Linux 5.13, 0 < 5.13, 5.15.209 ≤ 5.15.*, 6.1.175 ≤ 6.1.* …
Back to overview