{"id":"CVE-2026-64018","summary":"net: mana: validate rx_req_idx to prevent out-of-bounds array access","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: mana: validate rx_req_idx to prevent out-of-bounds array access\n\nIn mana_hwc_rx_event_handler(), rx_req_idx is derived from\nsge-\u003eaddress in DMA-coherent memory. In Confidential VMs\n(SEV-SNP/TDX), this memory is shared unencrypted and HW can modify\nWQE contents at any time. No bounds check exists on rx_req_idx,\nwhich can lead to an out-of-bounds access into reqs[].\n\nAdd bounds check on rx_req_idx in mana_hwc_rx_event_handler() before\nusing it to index the reqs[] array.","modified":"2026-07-22T03:31:39.368033444Z","published":"2026-07-19T15:39:12.704Z","database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64018.json"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/01f7f893d5e1baae995beeb86cd0f3e6bb2a3b01"},{"type":"WEB","url":"https://git.kernel.org/stable/c/355e9f2b2a7887ca38100127989af3e422ba71d0"},{"type":"WEB","url":"https://git.kernel.org/stable/c/5ddc715324badd7f2641bc177db1d027b402adae"},{"type":"WEB","url":"https://git.kernel.org/stable/c/763a372d344fb12fae566d36ddb46e92454ad58c"},{"type":"WEB","url":"https://git.kernel.org/stable/c/b809d0409991b75a6cff846a5ac27c3062953f84"},{"type":"WEB","url":"https://git.kernel.org/stable/c/fa627a5eaa83fc0261f44ef3769693b886ca6e27"},{"type":"WEB","url":"https://git.kernel.org/stable/c/ff1d5af207bcea857d45fe81505f1bc4b29eaef0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64018.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-64018"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f"},{"fixed":"5ddc715324badd7f2641bc177db1d027b402adae"},{"fixed":"ff1d5af207bcea857d45fe81505f1bc4b29eaef0"},{"fixed":"01f7f893d5e1baae995beeb86cd0f3e6bb2a3b01"},{"fixed":"763a372d344fb12fae566d36ddb46e92454ad58c"},{"fixed":"fa627a5eaa83fc0261f44ef3769693b886ca6e27"},{"fixed":"355e9f2b2a7887ca38100127989af3e422ba71d0"},{"fixed":"b809d0409991b75a6cff846a5ac27c3062953f84"}]}],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-64018.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.13.0"},{"fixed":"5.15.209"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.16.0"},{"fixed":"6.1.175"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.2.0"},{"fixed":"6.6.142"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.7.0"},{"fixed":"6.12.92"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.34"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.0.11"}]}],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-64018.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"}]}