CVE-2026-64540
Linux kernel usbnet gl620a out-of-bounds read leaks kernel heap via crafted USB packets
Is CVE-2026-64540 being exploited?
Not confirmed. CVE-2026-64540 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.27% probability of exploitation in the next 30 days.
How severe is CVE-2026-64540?
CVE-2026-64540 is rated High with a CVSS score of 8.1. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-64540?
Yes. A fix has been recorded for CVE-2026-64540. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-64540 affect?
CVE-2026-64540 affects Linux kernel (usbnet gl620a driver), GeneLink GL620A USB adapters. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-64540?
Apply kernel update; block untrusted USB devices; disable gl620a/usbnet if unused
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Malicious GeneLink USB device can trigger a kernel heap OOB read, leaking kernel memory and possibly aiding privilege escalation.
Patch when possible
- affected>= 47ee3051c856cc2aa95d35d577a8cb37279d540f and < 255d03551f94c7bdd86c7d9181a70b21917d829f
- affected>= 47ee3051c856cc2aa95d35d577a8cb37279d540f and < 4359376e6238d89977a35086e47ca3b07f43e850
- affected>= 47ee3051c856cc2aa95d35d577a8cb37279d540f and < 8624e179fa3ce23c2fbd1a198ce30764b73f054a
- affected>= 47ee3051c856cc2aa95d35d577a8cb37279d540f and < 573418f7ea8f859a841417eb4b915594094fd967
- affected>= 47ee3051c856cc2aa95d35d577a8cb37279d540f and < 0575599e451aff3c5329922562374a2cab25fc51
- affected>= 47ee3051c856cc2aa95d35d577a8cb37279d540f and < 0a7d9c7c5f1f208c523abbb4db6aea7bc1fad3db
- affected>= 47ee3051c856cc2aa95d35d577a8cb37279d540f and < 3ef79fa3860e644c8de7834fa7300e1c58f38862
- affected>= 47ee3051c856cc2aa95d35d577a8cb37279d540f and < 8ff7f2a6da4fccaa5cc9be7251a24e71e29fbd1a
- affected2.6.14
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.