Threadlinqs IntelligenceStart free

VulnerabilityCVE-2026-64527Published 2026-07-25

CVE-2026-64527 — Linux

As of 2026-07-25, CVE-2026-64527 is a vulnerability in Linux, EPSS 0.1% (5.6th percentile). No Threadlinqs-tracked threat campaign has been attributed to CVE-2026-64527 as of 2026-07-25; the identifier is re-checked against the Threadlinqs threat corpus on every daily ingest.

CVSS
—Not yet scored
EPSS
0.1%Higher than 5.6% of scored CVEs
CISA KEV
NoNot in the KEV catalog
Tracked threats
0None linked yet
Priority
0.2/10Threadlinqs triage score
Published
EPSS 0.1% (higher than 5.6% of all scored CVEs) · Priority 0.2/10 · Published 2026-07-25

Last updated:

What is CVE-2026-64527?

In the Linux kernel, the following vulnerability has been resolved: drm/hyperv: validate VMBus packet size in receive callback hyperv_receive_sub() reads msg->vid_hdr.type and dispatches into one of four message-type branches without knowing how many bytes the host wrote into hv->recv_buf. The completion path then runs memcpy(hv->init_buf, msg, VMBUS_MAX_PACKET_SIZE), so the consumer that wakes on wait_for_completion_timeout() can read up to 16 KiB of residue from a prior message as if it were the response payload. Pass bytes_recvd into hyperv_receive_sub() and reject any packet that does not cover the pipe + synthvid header. A single switch on msg->vid_hdr.type then computes the type-specific payload size: the three completion-driving types (SYNTHVID_VERSION_RESPONSE, SYNTHVID_RESOLUTION_RESPONSE, SYNTHVID_VRAM_LOCATION_ACK) fall through to a shared exit that requires that size before memcpy/complete, while SYNTHVID_FEATURE_CHANGE validates its own payload and returns before reading is_dirt_needed. Unknown types are dropped. SYNTHVID_RESOLUTION_RESPONSE is variable length: the host fills resolution_count entries, not the full SYNTHVID_MAX_RESOLUTION_COUNT array. Validate the fixed prefix first so resolution_count can be read, bound it against the array, then require only the count-sized array, so the shorter responses the host actually sends are accepted. Only run the sub-handler when vmbus_recvpacket() returned success. The memcpy length is bytes_recvd, which is bounded by VMBUS_MAX_PACKET_SIZE only on a successful receive; on -ENOBUFS vmbus_recvpacket() instead reports the required length, which can exceed hv->recv_buf, so copying bytes_recvd would read and write past the 16 KiB buffers. Gating on the success return keeps the copy bounded. The nonzero-return path is itself a malformed-message case and is now logged rather than silently skipped; channel recovery is not attempted. Rejected packets are reported via drm_err_ratelimited() rather than silently dropped, matching the CoCo-hardened pattern in hv_kvp_onchannelcallback().

1 affected-product entry is recorded, across 1 vendor, listed below. The identifier was first published 72 days ago.

Severity and exploitation probability

EPSS (FIRST)
0.1% probability of exploitation in the next 30 days, higher than 5.6% of all scored CVEs
CISA KEV
Not listed in the CISA Known Exploited Vulnerabilities catalog
Threadlinqs priority
0.2/10 — a Threadlinqs composite of the CVSS base score, the EPSS percentile and public exploit availability
Published
2026-07-25

Is CVE-2026-64527 being exploited?

It currently carries a trending score of 31 in the Threadlinqs vulnerability feed.

Affected products and versions

How to fix CVE-2026-64527

No vendor patch reference has been recorded for CVE-2026-64527 in the tracked sources. Follow the references below for a fix, and treat the products listed above as exposed until the vendor states otherwise.

Threat activity tracking CVE-2026-64527

No threat campaign in the Threadlinqs corpus currently references CVE-2026-64527, in its CVE list or as an indicator. The linkage is recomputed from the live corpus on every daily ingest, so this section fills in as soon as a tracked campaign cites the identifier.

Sources

Enriched from CVE.org, NVD, FIRST EPSS. Last verified by Threadlinqs on . This product uses the NVD API but is not endorsed or certified by the NVD.

Other references

Showing 5 of 7 recorded references.