Review reviewHigh

CVE-2026-64547

Linux

In the Linux kernel, the following vulnerability has been resolved: net: usb: net1080: validate packet_len before pad-byte access in rx_fixup For an even packet_len, net1080_rx_fixup() reads the pad byte at skb->data[packet_len] before the skb->len != packet_len check further down, and packet_len is only bounded against NC_MAX_PACKET. A malicious NetChip 1080 device can send a short frame advertising a large even packet_len (e.g. 0x4000), so the pad-byte read lands past the end of the skb: BUG: KASAN: slab-out-of-bounds in net1080_rx_fixup Read of size 1 at addr ffff8880106c83c6 by task kso...

CVSS
8.1
EPSS
-
- percentile
CISA KEV
Not listed
Published
2026.07.28
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability-
Technical severityCVSS 8.1

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: net: usb: net1080: validate packet_len before pad-byte access in rx_fixup For an even packet_len, net1080_rx_fixup() reads the pad byte at skb->data[packet_len] before the skb->len != packet_len check further down, and packet_len is only bounded against NC_MAX_PACKET. A malicious NetChip 1080 device can send a short frame advertising a large even packet_len (e.g. 0x4000), so the pad-byte read lands past the end of the skb: BUG: KASAN: slab-out-of-bounds in net1080_rx_fixup Read of size 1 at addr ffff8880106c83c6 by task kso...

Affected product and versions

Product
Linux
Affected versions
>= 904813cd8a0b334189da285bb05af0b18b062502 < f42217fa7d535e9ec4151f7971f06f6ea65e850a, >= 904813cd8a0b334189da285bb05af0b18b062502 < c087749815379e9af2fdbeb08bfc33870b103958, >= 904813cd8a0b334189da285bb05af0b18b062502 < e4a87126c085b097d29e17e3b7647295bba8be7c, >= 904813cd8a0b334189da285bb05af0b18b062502 < 685e92934f11d5e215dad58813e2f9955ac2f436, >= 904813cd8a0b334189da285bb05af0b18b062502 < 4dc8484be3302d187274364820d3bef6c62bde32, >= 904813cd8a0b334189da285bb05af0b18b062502 < b153cfe84b1340c69a13d0957665a2bfcf21239c, >= 904813cd8a0b334189da285bb05af0b18b062502 < ea866cab12db1a2100b400a8b03569e5bc0ee29a, >= 904813cd8a0b334189da285bb05af0b18b062502 < 03f384bc0cb8d4a1301d4f5b0baef2d980258383, >= 2.6.14
Fixed versions
No verified fixed-version field is available yet

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
CWE
Not available
CVE-2026-64547 — Linux | SECUFOCUS NOW