Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-64034— net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Linux kernel是美国Linux基金会开源的一款操作系统内核。 Linux kernel 5.13版本存在安全漏洞,该漏洞源于DMA缓冲区中hwc_msg_id存在TOCTOU双重获取问题,可能导致硬件修改检查与使用之间的值,绕过边界验证。

CVSS 9.3 · Critical EPSS 0.21% · P10

Affected Version Matrix 16

VendorProduct Version RangeStatus
Linux Linux ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f< a201c66edf2ebc6cfdc3813a889ba20fecebfae3 affected
ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f< 70ad2dff8d052a85dfef15715b531f38a29108cf affected
ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f< 566f42fb67a7ebfed6650e407e5b72e6b3e83bf7 affected
ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f< 6180a06bbc99fd9114b8db4be6c4d46e40f046ef affected
ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f< 09ec063d87c2dd3fa6f3561361a017bd882e9f37 affected
ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f< 3c4db56ccd13dd020fbf43afabaee74a40ec75e4 affected
ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f< 35f0f0a2536a4d604b4dbad92c85c4a8fdebb870 affected
5.13 affected
… +8 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-64034

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer In mana_hwc_rx_event_handler(), resp->response.hwc_msg_id is read from DMA-coherent memory and bounds-checked, then mana_hwc_handle_resp() re-reads the same field from the same DMA buffer for test_bit() and pointer arithmetic. DMA-coherent memory is mapped uncacheable on x86 and is shared, unencrypted, in Confidential VMs (SEV-SNP/TDX), so each load goes directly to host-visible memory. A H/W can modify the value between the check and the use, bypassing the bounds validation. Fix this by reading hwc_msg_id exactly once using READ_ONCE() into a stack-local variable in mana_hwc_rx_event_handler(), and passing the validated value as a parameter to mana_hwc_handle_resp().
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会开源的一款操作系统内核。 Linux kernel 5.13版本存在安全漏洞,该漏洞源于DMA缓冲区中hwc_msg_id存在TOCTOU双重获取问题,可能导致硬件修改检查与使用之间的值,绕过边界验证。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f ~ a201c66edf2ebc6cfdc3813a889ba20fecebfae3 -
Linux Linux 5.13 -

II. Public POCs for CVE-2026-64034

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-64034

登录查看更多情报信息。

Patches & Fixes for CVE-2026-64034 (7)

Same Patch Batch · Linux · 2026-07-19 · 429 CVEs total

CVE-2026-63795 10.0 CRITICAL 9p: avoid putting oldfid in p9_client_walk() error path
CVE-2026-63979 9.8 CRITICAL net/handshake: hand off the pinned file reference to accept_doit
CVE-2026-53399 9.8 CRITICAL nfsd: release layout stid on setlease failure
CVE-2026-53398 9.8 CRITICAL NFSD: Fix SECINFO_NO_NAME decode error cleanup
CVE-2026-64089 9.8 CRITICAL batman-adv: tt: fix negative last_changeset_len
CVE-2026-64025 9.8 CRITICAL bpf, skmsg: fix verdict sk_data_ready racing with ktls rx
CVE-2026-64113 9.8 CRITICAL ixgbevf: fix use-after-free in VEPA multicast source pruning
CVE-2026-63924 9.8 CRITICAL ipv6: exthdrs: refresh nh pointer after ipv6_hop_jumbo()
CVE-2026-64055 9.8 CRITICAL net: ethernet: cortina: Carry over frag counter
CVE-2026-63984 9.8 CRITICAL ipv6: rpl: fix hdrlen overflow in ipv6_rpl_srh_decompress()
CVE-2026-63800 9.8 CRITICAL pNFS: Fix use-after-free in pnfs_update_layout()
CVE-2026-64037 9.8 CRITICAL wifi: iwlwifi: mld: fix TSO segmentation explosion when AMSDU is disabled
CVE-2026-63888 9.8 CRITICAL scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd()
CVE-2026-63887 9.8 CRITICAL scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf
CVE-2026-64136 9.8 CRITICAL smb: client: protect tc_count increment in smb2_find_smb_sess_tcon_unlocked()
CVE-2026-64102 9.8 CRITICAL RDMA/siw: Reject MPA FPDU length underflow before signed receive math
CVE-2026-64125 9.8 CRITICAL net: bcmgenet: keep RBUF EEE/PM disabled
CVE-2026-64061 9.8 CRITICAL netfs: Fix early put of sink folio in netfs_read_gaps()
CVE-2026-64056 9.8 CRITICAL net: ethernet: cortina: Make RX SKB per-port
CVE-2026-63825 9.8 CRITICAL gcov: use atomic counter updates to fix concurrent access crashes

Showing top 20 of 429 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-64034

No comments yet


Leave a comment