Description
In the Linux kernel, the following vulnerability has been resolved:

xdp: fix zero-copy frame layout

xdp_convert_zc_to_xdp_frame() clones an XSK packet into an order-0 page
and advertises PAGE_SIZE as its frame size. It allows the copied frame
to occupy the page tail needed by skb_shared_info and records zero
headroom even when metadata separates the frame header from packet data.
An AF_XDP zero-copy packet redirected through cpumap can therefore make
the skb overlap skb_shared_info or place it beyond the allocated page.

Limit the copied layout to SKB_WITH_OVERHEAD(PAGE_SIZE) and include the
metadata length in frame headroom. Redirect callers already handle a
NULL conversion result.

BUG: KASAN: slab-out-of-bounds in skb_gro_receive
Write of size 4 at addr ffff88800cf37004 by task cpumap/1/map:1/146
Call Trace:
skb_gro_receive (net/core/gro.c:174)
udp_gro_receive (net/ipv4/udp_offload.c:812)
inet_gro_receive (net/ipv4/af_inet.c:1539)
dev_gro_receive (net/core/gro.c:515)
gro_receive_skb (net/core/gro.c:633)
cpu_map_kthread_run (kernel/bpf/cpumap.c:395)
kthread (kernel/kthread.c:436)
ret_from_fork (arch/x86/kernel/process.c:164)
ret_from_fork_asm (arch/x86/entry/entry_64.S:255)
Kernel panic - not syncing: KASAN: panic_on_warn set ...
Published: 2026-09-11
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Kernel out‑of‑bounds memory corruption leading to system crash
Action: Immediate patch
AI Analysis

Impact

The vulnerability arises in the Linux kernel's xdp which copies an AF_XDP packet into an order‑0 page while advertising a frame size of PAGE_SIZE. Because the skb_shared_info tail is not omitted and the frame headroom is zero, the cloned packet can overlap or extend beyond the allocated page, leading to an out‑of‑bounds write during GRO packet processing. This memory corruption can trigger a KASAN error and ultimately cause a kernel panic, rendering the system unavailable.

Affected Systems

The flaw affects all Linux kernel releases that included the buggy implementation of xdp_convert_zc_to_xdp_frame prior to the patch commits referenced. In particular, any kernel before the fixes introduced at commit 6de17275b3ccdf9887568b07e54da2e3597217cf (and earlier commits such as 15d1f3c0dbe7a740f779337deb39f23cd8d002c8) is vulnerable. All architectures that support cpumap impacted.

Risk and Exploitability

With a CVSS score of 9.8 the vulnerability is considered critical. The EPSS score of < 1 % indicates a low current exploitation probability, and the feature is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a malicious AF_XDP packet sent through cpumap to a kernel module that processes such packets. An attacker who can inject crafted data into a vulnerable AF_XDP socket may trigger the out‑of‑bounds write, potentially bringing the kernel to a halt. Local privilege escalation or local users who can open AF_XDP sockets are sufficient namespaces further widens the attack surface.

Generated by OpenCVE AI on September 21, 2026 at 02:42 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that incorporates the patches committed at 6de17275b3ccdf9887568b07e54da2e3597217cf and earlier commits such as 15d1f3c0dbe7a740f779337deb39f23cd8d002c8. Kernel distributions often ship a later stable release that contains these fixes.
  • If a kernel upgrade is not immediately feasible, disable or restrict AF_XDP zero‑copy and cpumap usage for sockets that handle untrusted traffic. Stopping cpumap‑based packet redirection from externally reachable interfaces mitigates the risk.
  • Continuously panic messages that indicate out‑of‑bounds writes, and apply additional kernel hardening such as enforcing SELinux or AppArmor confinement to limit local user privileges from opening AF_XDP sockets.

Generated by OpenCVE AI on September 21, 2026 at 02:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 14 Sep 2026 12:30:00 +0000


Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Important


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: xdp: fix zero-copy frame layout xdp_convert_zc_to_xdp_frame() clones an XSK packet into an order-0 page and advertises PAGE_SIZE as its frame size. It allows the copied frame to occupy the page tail needed by skb_shared_info and records zero headroom even when metadata separates the frame header from packet data. An AF_XDP zero-copy packet redirected through cpumap can therefore make the skb overlap skb_shared_info or place it beyond the allocated page. Limit the copied layout to SKB_WITH_OVERHEAD(PAGE_SIZE) and include the metadata length in frame headroom. Redirect callers already handle a NULL conversion result. BUG: KASAN: slab-out-of-bounds in skb_gro_receive Write of size 4 at addr ffff88800cf37004 by task cpumap/1/map:1/146 Call Trace: skb_gro_receive (net/core/gro.c:174) udp_gro_receive (net/ipv4/udp_offload.c:812) inet_gro_receive (net/ipv4/af_inet.c:1539) dev_gro_receive (net/core/gro.c:515) gro_receive_skb (net/core/gro.c:633) cpu_map_kthread_run (kernel/bpf/cpumap.c:395) kthread (kernel/kthread.c:436) ret_from_fork (arch/x86/kernel/process.c:164) ret_from_fork_asm (arch/x86/entry/entry_64.S:255) Kernel panic - not syncing: KASAN: panic_on_warn set ...
Title xdp: fix zero-copy frame layout
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T11:59:37.447Z

Reserved: 2026-08-26T14:34:25.812Z

Link: CVE-2026-81002

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:08.483

Modified: 2026-09-14T13:18:54.553

Link: CVE-2026-81002

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-11T19:42:55Z

Links: CVE-2026-81002 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T02:45:08Z

Weaknesses