# CVE-2026-64527 — Linux

> As of 2026-07-25, CVE-2026-64527 is a vulnerability in Linux, EPSS 0.1% (5.6th percentile). No Threadlinqs-tracked threat campaign has been attributed to CVE-2026-64527 as of 2026-07-25; the identifier is re-checked against the Threadlinqs threat corpus on every daily ingest.

**Last updated:** 2026-07-25

## What is CVE-2026-64527?

In the Linux kernel, the following vulnerability has been resolved: drm/hyperv: validate VMBus packet size in receive callback hyperv_receive_sub() reads msg->vid_hdr.type and dispatches into one of four message-type branches without knowing how many bytes the host wrote into hv->recv_buf. The completion path then runs memcpy(hv->init_buf, msg, VMBUS_MAX_PACKET_SIZE), so the consumer that wakes on wait_for_completion_timeout() can read up to 16 KiB of residue from a prior message as if it were the response payload. Pass bytes_recvd into hyperv_receive_sub() and reject any packet that does not cover the pipe + synthvid header. A single switch on msg->vid_hdr.type then computes the type-specific payload size: the three completion-driving types (SYNTHVID_VERSION_RESPONSE, SYNTHVID_RESOLUTION_RESPONSE, SYNTHVID_VRAM_LOCATION_ACK) fall through to a shared exit that requires that size before memcpy/complete, while SYNTHVID_FEATURE_CHANGE validates its own payload and returns before reading is_dirt_needed. Unknown types are dropped. SYNTHVID_RESOLUTION_RESPONSE is variable length: the host fills resolution_count entries, not the full SYNTHVID_MAX_RESOLUTION_COUNT array. Validate the fixed prefix first so resolution_count can be read, bound it against the array, then require only the count-sized array, so the shorter responses the host actually sends are accepted. Only run the sub-handler when vmbus_recvpacket() returned success. The memcpy length is bytes_recvd, which is bounded by VMBUS_MAX_PACKET_SIZE only on a successful receive; on -ENOBUFS vmbus_recvpacket() instead reports the required length, which can exceed hv->recv_buf, so copying bytes_recvd would read and write past the 16 KiB buffers. Gating on the success return keeps the copy bounded. The nonzero-return path is itself a malformed-message case and is now logged rather than silently skipped; channel recovery is not attempted. Rejected packets are reported via drm_err_ratelimited() rather than silently dropped, matching the CoCo-hardened pattern in hv_kvp_onchannelcallback().

1 affected-product entry is recorded, across 1 vendor, listed below. The identifier was first published 72 days ago.

## Severity and exploitation probability

- **EPSS (FIRST):** 0.1% probability of exploitation in the next 30 days, higher than 5.6% of all scored CVEs
- **CISA KEV:** Not listed in the CISA Known Exploited Vulnerabilities catalog
- **Threadlinqs priority:** 0.2/10 — a Threadlinqs composite of the CVSS base score, the EPSS percentile and public exploit availability
- **Published:** 2026-07-25

## Is CVE-2026-64527 being exploited?

It currently carries a trending score of 31 in the Threadlinqs vulnerability feed.

## Affected products and versions

- [Linux](https://intel.threadlinqs.com/vendors/linux): Linux

## How to fix CVE-2026-64527

No vendor patch reference has been recorded for CVE-2026-64527 in the tracked sources. Follow the references below for a fix, and treat the products listed above as exposed until the vendor states otherwise.

## Threat activity tracking CVE-2026-64527

No threat campaign in the Threadlinqs corpus currently references CVE-2026-64527, in its CVE list or as an indicator. The linkage is recomputed from the live corpus on every daily ingest, so this section fills in as soon as a tracked campaign cites the identifier.

## Sources

Enriched from CVE.org, NVD, FIRST EPSS. Last verified by Threadlinqs on 2026-07-26. This product uses the NVD API but is not endorsed or certified by the NVD.

**Other references**

- [git.kernel.org](https://git.kernel.org/stable/c/57d5d697642e05d5dd2d40660817765943dd709f)
- [git.kernel.org (f5251226551bfec98c4705641b6f94ff1f238d91)](https://git.kernel.org/stable/c/f5251226551bfec98c4705641b6f94ff1f238d91)
- [git.kernel.org (049a6b474823049fe60212f25f26e4b30f44ee8f)](https://git.kernel.org/stable/c/049a6b474823049fe60212f25f26e4b30f44ee8f)
- [git.kernel.org (588c84b461393ff1998ac7b97b04f953f642e0df)](https://git.kernel.org/stable/c/588c84b461393ff1998ac7b97b04f953f642e0df)
- [git.kernel.org (164dc7bf17609340233c6bf4f66bb7c7008a0511)](https://git.kernel.org/stable/c/164dc7bf17609340233c6bf4f66bb7c7008a0511)

_Showing 5 of 7 recorded references._

Canonical: https://intel.threadlinqs.com/cve/CVE-2026-64527
Full detection coverage and IOCs for threats exploiting CVE-2026-64527 via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
