CVE-2026-64034

Source
https://cve.org/CVERecord?id=CVE-2026-64034
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-64034.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-64034
Downstream
Published
2026-07-19T15:39:23.470Z
Modified
2026-07-22T03:31:57.216697115Z
Severity
  • 9.3 (Critical) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H CVSS Calculator
Summary
net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer
Details

In the Linux kernel, the following vulnerability has been resolved:

net: mana: Fix TOCTOU double-fetch of hwcmsgid from DMA buffer

In manahwcrxeventhandler(), resp->response.hwcmsgid is read from DMA-coherent memory and bounds-checked, then manahwchandleresp() re-reads the same field from the same DMA buffer for testbit() and pointer arithmetic.

DMA-coherent memory is mapped uncacheable on x86 and is shared, unencrypted, in Confidential VMs (SEV-SNP/TDX), so each load goes directly to host-visible memory. A H/W can modify the value between the check and the use, bypassing the bounds validation.

Fix this by reading hwcmsgid exactly once using READONCE() into a stack-local variable in manahwcrxeventhandler(), and passing the validated value as a parameter to manahwchandleresp().

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64034.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f
Fixed
a201c66edf2ebc6cfdc3813a889ba20fecebfae3
Fixed
70ad2dff8d052a85dfef15715b531f38a29108cf
Fixed
566f42fb67a7ebfed6650e407e5b72e6b3e83bf7
Fixed
6180a06bbc99fd9114b8db4be6c4d46e40f046ef
Fixed
09ec063d87c2dd3fa6f3561361a017bd882e9f37
Fixed
3c4db56ccd13dd020fbf43afabaee74a40ec75e4
Fixed
35f0f0a2536a4d604b4dbad92c85c4a8fdebb870

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-64034.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.13.0
Fixed
5.15.209
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.175
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.142
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.92
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.34
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.0.11

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-64034.json"