CVE-2026-64018
Published Jul 19, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: net: mana: validate rx_req_idx to prevent out-of-bounds array access In mana_hwc_rx_event_handler(), rx_req_idx is derived from sge->address in DMA-coherent memory. In Confidential VMs (SEV-SNP/TDX), this memory is shared unencrypted and HW can modify WQE contents at any time. No bounds check exists on rx_req_idx, which can lead to an out-of-bounds access into reqs[]. Add bounds check on rx_req_idx in mana_hwc_rx_event_handler() before using it to index the reqs[] array.
Is your site exposed to CVE-2026-64018?
Run a free security scan — no signup, results in seconds.
References
Other References
https://git.kernel.org/stable/c/01f7f893d5e1baae995beeb86cd0f3e6bb2a3b01
https://git.kernel.org/stable/c/355e9f2b2a7887ca38100127989af3e422ba71d0
https://git.kernel.org/stable/c/5ddc715324badd7f2641bc177db1d027b402adae
https://git.kernel.org/stable/c/763a372d344fb12fae566d36ddb46e92454ad58c
https://git.kernel.org/stable/c/b809d0409991b75a6cff846a5ac27c3062953f84
https://git.kernel.org/stable/c/fa627a5eaa83fc0261f44ef3769693b886ca6e27
https://git.kernel.org/stable/c/ff1d5af207bcea857d45fe81505f1bc4b29eaef0
Frequently Asked Questions
What is CVE-2026-64018? +
In the Linux kernel, the following vulnerability has been resolved:
net: mana: validate rx_req_idx to prevent out-of-bounds array access
In mana_hwc_rx_event_handler(), rx_req_idx is derived from
sge->address in DMA-coherent memory. In Confidential VMs
(SEV-SNP/TDX), this memory is shared unencrypted and HW can modify
WQE contents at any time. No bounds check exists on rx_req_idx,
which can lead to an out-of-bounds access into reqs[].
Add bounds check on rx_req_idx in mana_hwc_rx_event_handler() before
using it to index the reqs[] array.
How do I check if I'm vulnerable to CVE-2026-64018? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.