CVE-2026-64035
A critical flaw in the Linux kernel’s igc network driver could cause incorrect cleanup of transmitted packets, potentially leading to system instability. The issue arises when the driver reuses transmit buffers without resetting their type, allowing stale XDP or XSK types to persist. The flaw has been fixed by setting the buffer type to IGC_TX_BUFFER_TYPE_SKB.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Linux kernel users running the igc driver on versions prior to the fix, i.e., any system that has not yet applied the kernel update containing the patch.
Real-world impact
An attacker could crash the system or cause network disruptions by exploiting the bug, leading to denial of service or degraded network performance.
Why this severity
The CVSS score of 9.8 reflects that the flaw is network‑exploitable, requires no privileges, and can compromise confidentiality, integrity, and availability of the affected system.
What to do about it
- 01Update the Linux kernel to a version that includes the fix for CVE-2026-64035.
NVD description indicates the vulnerability has been resolved.
Timeline
- Jul 19, 2026 · 14d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 20, 2026 · 13d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
- Jul 30, 2026 · 3d agoAdvisory updatedThe NVD record was last revised.