Review reviewHigh

CVE-2026-64540

Linux

In the Linux kernel, the following vulnerability has been resolved: usbnet: gl620a: fix out-of-bounds read in genelink_rx_fixup() genelink_rx_fixup() splits an aggregated RX frame into its individual packets, using a per-packet length taken from device-supplied data. That length is only bounded by GL_MAX_PACKET_LEN (1514); it is never compared against how many bytes were actually received. A malicious GeneLink (GL620A) device can therefore send a short URB whose header claims packet_count > 1 and a first packet of up to 1514 bytes. skb_put_data(gl_skb, packet->packet_data, size); then copie...

CVSS
8.1
EPSS
-
- percentile
CISA KEV
Not listed
Published
2026.07.28
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability-
Technical severityCVSS 8.1

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: usbnet: gl620a: fix out-of-bounds read in genelink_rx_fixup() genelink_rx_fixup() splits an aggregated RX frame into its individual packets, using a per-packet length taken from device-supplied data. That length is only bounded by GL_MAX_PACKET_LEN (1514); it is never compared against how many bytes were actually received. A malicious GeneLink (GL620A) device can therefore send a short URB whose header claims packet_count > 1 and a first packet of up to 1514 bytes. skb_put_data(gl_skb, packet->packet_data, size); then copie...

Affected product and versions

Product
Linux
Affected versions
>= 47ee3051c856cc2aa95d35d577a8cb37279d540f < 255d03551f94c7bdd86c7d9181a70b21917d829f, >= 47ee3051c856cc2aa95d35d577a8cb37279d540f < 4359376e6238d89977a35086e47ca3b07f43e850, >= 47ee3051c856cc2aa95d35d577a8cb37279d540f < 8624e179fa3ce23c2fbd1a198ce30764b73f054a, >= 47ee3051c856cc2aa95d35d577a8cb37279d540f < 573418f7ea8f859a841417eb4b915594094fd967, >= 47ee3051c856cc2aa95d35d577a8cb37279d540f < 0575599e451aff3c5329922562374a2cab25fc51, >= 47ee3051c856cc2aa95d35d577a8cb37279d540f < 0a7d9c7c5f1f208c523abbb4db6aea7bc1fad3db, >= 47ee3051c856cc2aa95d35d577a8cb37279d540f < 3ef79fa3860e644c8de7834fa7300e1c58f38862, >= 47ee3051c856cc2aa95d35d577a8cb37279d540f < 8ff7f2a6da4fccaa5cc9be7251a24e71e29fbd1a, >= 2.6.14
Fixed versions
No verified fixed-version field is available yet

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
CWE
Not available
CVE-2026-64540 — Linux | SECUFOCUS NOW