Description
In the Linux kernel, the following vulnerability has been resolved:

xfrm: iptfs: propagate SKBFL_SHARED_FRAG in iptfs_skb_add_frags()

When iptfs_skb_add_frags() copies frag references from the source
frag walk into a new SKB, it increments the page reference count via
__skb_frag_ref() but does not propagate SKBFL_SHARED_FRAG to the
destination SKB's skb_shinfo->flags.

If the source SKB carries shared frags (e.g. from a page-pool backed
receive path), the new inner SKB will appear to ESP as having privately
owned frags. A subsequent esp_input() call for a nested transport-mode
SA then takes the no-COW fast path and decrypts in place, writing over
pages that are still referenced by the outer IPTFS SKB. This causes
kernel-visible memory corruption and can trigger a panic.

All other frag-transfer helpers in the kernel (skb_try_coalesce,
skb_gro_receive, __pskb_copy_fclone, skb_shift, skb_segment) correctly
propagate SKBFL_SHARED_FRAG; align iptfs_skb_add_frags() with this
convention by setting the flag inside the loop immediately after
__skb_frag_ref() and nr_frags++, so every exit path that attaches a frag
unconditionally propagates SKBFL_SHARED_FRAG.
Published: 2026-08-05
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

In the Linux kernel, the helper that copies packet fragments, iptfs_skb_add_frags, fails to propagate the SKBFL_SHARED_FRAG flag when creating a new socket buffer. When a shared fragment is handled by the ESP decryption routine, the code mistakenly assumes exclusive ownership and performs an in-place decryption that overwrites pages still referenced by the outer packet. This results in kernel-visible memory corruption and can cause a system panic. The issue involves dereferencing a freed pointer (CWE‑821).

Affected Systems

Any Linux kernel that includes the unpatched iptfs_skb_add_frags function is potentially impacted. No specific version ranges are listed in the CVE data, so affected releases cannot be precisely identified.

Risk and Exploitability

The CVSS score of 9.8 indicates a critical severity, and the vulnerability can lead to a denial‑of‑service via kernel panic. The EPSS score of < 1% indicates a very low but non‑zero likelihood of exploitation. The flaw is not listed in CISA’s KEV catalog. The likely attack vector is the receipt of specially crafted network traffic that activates nested transport‑mode IPsec decryption on a packet carrying shared fragments; this inference follows from the description of the affected code path.

Generated by OpenCVE AI on August 8, 2026 at 16:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes the patch fixing SKBFL_SHARED_FRAG propagation; the relevant commits are listed in the provided references.
  • If an immediate kernel upgrade is not possible, disable or restrict nested transport‑mode IPsec services, as the problem only surfaces when such packets are processed.
  • Continuously monitor system logs for kernel panic messages or memory corruption indicators to detect attempts to exploit the flaw.

Generated by OpenCVE AI on August 8, 2026 at 16:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 08 Aug 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Thu, 06 Aug 2026 15:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
CWE-664

Thu, 06 Aug 2026 12:15:00 +0000


Wed, 05 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
CWE-664

Wed, 05 Aug 2026 08:15:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: xfrm: iptfs: propagate SKBFL_SHARED_FRAG in iptfs_skb_add_frags() When iptfs_skb_add_frags() copies frag references from the source frag walk into a new SKB, it increments the page reference count via __skb_frag_ref() but does not propagate SKBFL_SHARED_FRAG to the destination SKB's skb_shinfo->flags. If the source SKB carries shared frags (e.g. from a page-pool backed receive path), the new inner SKB will appear to ESP as having privately owned frags. A subsequent esp_input() call for a nested transport-mode SA then takes the no-COW fast path and decrypts in place, writing over pages that are still referenced by the outer IPTFS SKB. This causes kernel-visible memory corruption and can trigger a panic. All other frag-transfer helpers in the kernel (skb_try_coalesce, skb_gro_receive, __pskb_copy_fclone, skb_shift, skb_segment) correctly propagate SKBFL_SHARED_FRAG; align iptfs_skb_add_frags() with this convention by setting the flag inside the loop immediately after __skb_frag_ref() and nr_frags++, so every exit path that attaches a frag unconditionally propagates SKBFL_SHARED_FRAG.
Title xfrm: iptfs: propagate SKBFL_SHARED_FRAG in iptfs_skb_add_frags()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-17T04:57:44.387Z

Reserved: 2026-07-19T15:36:31.797Z

Link: CVE-2026-64566

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-05T08:16:36.140

Modified: 2026-08-17T05:18:02.473

Link: CVE-2026-64566

cve-icon Redhat

Severity :

Publid Date: 2026-08-05T00:00:00Z

Links: CVE-2026-64566 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-08T17:00:05Z

Weaknesses
  • CWE-821

    Incorrect Synchronization