CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-64000

Critical · CVSS 9.8
CVSS
9.8
nvd
EPSS
0.17%
7th pct
KEV
No
Class
oss containerizable

Description

In the Linux kernel, the following vulnerability has been resolved: net: hsr: fix potential OOB access in supervision frame handling Ensure the entire TLV header is linearized before access by adding sizeof(struct hsr_sup_tlv) to the pskb_may_pull() calls. Without this, a truncated frame could cause an out-of-bounds access.

Affected packages

Linux Kernel 5.16.0 → 6.1.176
Linux Kernel 6.13.0 → 6.18.35
Linux Kernel 6.19.0 → 7.0.12
Linux Kernel 6.2.0 → 6.6.143
Linux Kernel 6.7.0 → 6.12.93

References

Status: profiled · ingested 2026-07-20T18:00:18.000Z