CVE-2026-64527

Updated on 25 Jul 2026

Severity

7.0 High severity

Details

CVSS score
7.0

Overview

About vulnerability

A flaw was found in the drm/hyperv component of the Linux kernel. The hyperv_receive_sub() function, responsible for processing VMBus packets, does not adequately validate the size of incoming data. This oversight allows a malicious or compromised host to send specially crafted packets, potentially causing the system to read up to 16 KiB of unintended data from memory. This could lead to information disclosure or memory corruption within the kernel.

Details

KernelCare state

Live-patch status from KernelCare for each operating system.

Operating system Status Covered kernels
Debian 12 Planned