CRITICAL Introduced in 4.16
gemini RxFrag Corruption
CVE-2026-64055
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
KernelScan AI9.8CRITICAL
01Description
In the Linux kernel, the following vulnerability has been resolved: net: ethernet: cortina: Carry over frag counter The gmac_rx() NAPI poll function assembles packets in an SKB from a ring buffer. If the ring buffer gets completely emptied during a poll cycle, we exit gmac_rx(), but the packet is not yet completely assembled in the SKB, yet the fragment counter frag_nr is reset to zero on the next invocation. Solve this by making the RX fragment counter a part of the port struct, and carry it over between invocations. Reset the fragment counter only right after calling napi_gro_frags(), on error (after calling napi_free_frags()) or if stopping the port. Reset it in some place where not strictly necessary just to emphasize what is going on. This was found by Sashiko during normal patch review.
02KernelScan AI Analysis
Risk summary
A remote attacker can send network traffic to a system using the Cortina Gemini Ethernet driver to corrupt packet reassembly state in the kernel. The frag_nr counter is reset to zero on each NAPI poll invocation, so a multi-fragment packet spanning multiple poll cycles is assembled incorrectly. This causes memory corruption in the SKB structure, which can lead to information disclosure, arbitrary kernel memory modification, or a kernel panic, resulting in complete system compromise or denial of service.
Vulnerability analysis
The root cause is that the local variable frag_nr in gmac_rx() is initialized to 0 on every invocation of the NAPI poll function. When the RX ring buffer is exhausted mid-packet (i.e., a multi-fragment packet spans two poll cycles), the fragment counter is reset, causing subsequent fragments to be placed at wrong indices in the SKB fragment array. This constitutes memory buffer corruption: subsequent calls to skb_add_rx_frag() overwrite earlier fragment entries and corrupt SKB length and page-tracking state. The fix moves frag_nr into the persistent port struct as rx_frag_nr, loading it at the start of gmac_rx() and writing it back at the end, so state is correctly carried across poll cycles. The counter is only reset to zero after napi_gro_frags() (packet complete), napi_free_frags() (error/drop), or gmac_stop() (port shutdown). The attack surface is systems using the Cortina/Gemini Ethernet hardware (StorLink SL3512/SL3516 SoCs); triggering the bug requires receiving network traffic that results in multi-fragment packets spanning poll boundaries, which can be induced by a remote sender. No privileges are required on the target system.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| 6.12 | 4.16 | 6.12.92 | 7123cf481e21 |
| 6.1 | 4.16 | 6.1.175 | 75105fcf73f1 |
| 6.18 | 4.16 | 6.18.34 | c373b34877af |
| 7.0 | 4.16 | 7.0.11 | 46806096f35b |
| 6.6 | 4.16 | 6.6.142 | 78cf08b3be47 |
| 5.15 | 4.16 | 5.15.209 | 7af1fabdee74 |
| 5.10 | 4.16 | 5.10.258 | df31e3b64455 |
| mainline | 4.16 | 7.1 | ebd8ec2b309e |