CVE-2026-64056
A race condition in the Linux kernel’s Ethernet driver can let an attacker crash or destabilize the system by exploiting how packet fragments are assembled. The flaw was fixed in a kernel update. Users should update to a patched kernel.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
All Linux systems running a kernel version before the patch that fixed CVE-2026-64056, especially those with dual‑port Ethernet hardware.
Real-world impact
An attacker could trigger a crash or denial of service by sending crafted network traffic that exploits the race between the two Ethernet ports.
Why this severity
The CVSS score is high because the flaw can be triggered over the network without authentication, and it can compromise confidentiality, integrity, and availability.
What to do about it
- 01Upgrade the Linux kernel to a version that includes the fix for CVE-2026-64056.
- 02Reboot the system to load the updated kernel.
NVD-referenced vendor advisory
Timeline
- Jul 19, 2026 · 14d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 20, 2026 · 13d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
- Jul 30, 2026 · 3d agoAdvisory updatedThe NVD record was last revised.
How it’s attacked
References & advisories
- git.kernel.org/stable/c/06937db21ee311ed07…
- git.kernel.org/stable/c/27856d533eca380400…
- git.kernel.org/stable/c/3b249988d774dacf13…
- git.kernel.org/stable/c/67a35e7da7ef9d2f00…
- git.kernel.org/stable/c/6bba24e9ebe6f1c0b3…
- git.kernel.org/stable/c/72158ea185b27afae1…
- git.kernel.org/stable/c/b6b22824b30e48ce1d…
- git.kernel.org/stable/c/cfd62907f3cdbc3b6d…