Description
In the Linux kernel, the following vulnerability has been resolved:

net: skbuff: don't touch shared zerocopy state in skb_tx_error()

skb_tx_error() completes the zerocopy uarg and clears
SKBFL_ALL_ZEROCOPY, and skb_zcopy_downgrade_managed() clears
SKBFL_MANAGED_FRAG_REFS. Both live in skb_shinfo(), which every clone
shares, while the caller only owns the reference it is about to drop.
Through a clone it tells the producer its pages are free and drops
SKBFL_SHARED_FRAG for an skb that is still in flight.

Open vSwitch reaches this with a non-last OVS_ACTION_ATTR_RECIRC:
clone_execute() sends a skb_clone() into ovs_dp_process_packet() while
do_execute_actions() keeps forwarding the original, and skb_clone()
does not privatise the frags here -- skb_orphan_frags() returns early
on SKBFL_DONT_ORPHAN. A flow miss on the clone then strips the marker
from the packet still being forwarded, and a later local ESP delivery
decrypts in place over frags it does not own privately.

Skip it for a cloned skb. Nothing is lost: skb_release_data() clears
the zerocopy state once the last reference to the shared data goes.
Published: 2026-09-11
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Memory corruption possibly leading to privilege escalation or remote
Action: Apply Kernel Patch
AI Analysis

Impact

A defect in the Linux kernel’s skb_tx_error() routine incorrectly clears shared zerocopy state from a sk_buff clone. This results in a cloned packet still in flight being altered, causing kernel memory corruption. In an Open vSwitch environment, packets that trigger non‑last recirculation can lead to this flaw and potentially corrupt data used for ESP decryption, giving an attacker the ability to inject malicious code or elevate privileges.

Affected Systems

All Linux kernel releases that do not contain the commit that patches the skb_tx_error() handling are affected. The vulnerability is triggered when Open vSwitch processes packets that go through a non‑last OVS_ACTION_ATTR_RECIRC action, which causes a skb_clone() to be sent into the downstream processing path without privatizing fragments.

Risk and Exploitability

The CVSS base score of 7.8 denotes high severity, yet the EPSS score of < 1% indicates a very low probability of exploitation in the wild. The vulnerability is not listed in CISA KEV, implying that no publicly available, weapon. The likely attack vector is remote network traffic sent to an Open vSwitch instance that runs on a vulnerable Linux kernel and could be exploited by sending specially crafted packets that trigger the recirculation path.

Generated by OpenCVE AI on September 21, 2026 at 02:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes the patch for skb_tx_error() (e.g., a release that incorporates commit 0370da114a9bc044e248b85c6809d1b5e0c1f7f9) or later stable release.
  • If Open vSwitch is in use, upgrade to a version that incorporates the kernel fix or apply any vendor‑issued patch that removes skb_clone() from the recirculation path.
  • Reconfigure Open vSwitch to avoid using non‑last OVS_ACTION_ATTR_RECIRC actions or disable recirculation temporarily until the kernel patch is applied.

Generated by OpenCVE AI on September 21, 2026 at 02:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 14 Sep 2026 12:30:00 +0000


Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H'}

cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-821
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H'}

threat_severity

Important


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: net: skbuff: don't touch shared zerocopy state in skb_tx_error() skb_tx_error() completes the zerocopy uarg and clears SKBFL_ALL_ZEROCOPY, and skb_zcopy_downgrade_managed() clears SKBFL_MANAGED_FRAG_REFS. Both live in skb_shinfo(), which every clone shares, while the caller only owns the reference it is about to drop. Through a clone it tells the producer its pages are free and drops SKBFL_SHARED_FRAG for an skb that is still in flight. Open vSwitch reaches this with a non-last OVS_ACTION_ATTR_RECIRC: clone_execute() sends a skb_clone() into ovs_dp_process_packet() while do_execute_actions() keeps forwarding the original, and skb_clone() does not privatise the frags here -- skb_orphan_frags() returns early on SKBFL_DONT_ORPHAN. A flow miss on the clone then strips the marker from the packet still being forwarded, and a later local ESP delivery decrypts in place over frags it does not own privately. Skip it for a cloned skb. Nothing is lost: skb_release_data() clears the zerocopy state once the last reference to the shared data goes.
Title net: skbuff: don't touch shared zerocopy state in skb_tx_error()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T11:59:22.460Z

Reserved: 2026-08-26T14:34:25.811Z

Link: CVE-2026-80977

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:04.013

Modified: 2026-09-14T13:18:52.487

Link: CVE-2026-80977

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-11T19:42:38Z

Links: CVE-2026-80977 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T02:30:08Z

Weaknesses
  • CWE-821

    Incorrect Synchronization