Description
In the Linux kernel, the following vulnerability has been resolved:

net: skbuff: don't skb_tx_error() the source skb in skb_zerocopy()

skb_zerocopy() copies frags from @from into @to. On an
skb_orphan_frags() failure it calls skb_tx_error(@from), a destructive
operation on the source skb the copy helper does not own. That completes
@from's zerocopy uarg and clears SKBFL_ALL_ZEROCOPY, including the
SKBFL_SHARED_FRAG page-ownership marker.

Both callers already report the failure on their own drop path.
nfnetlink_queue does it at nla_put_failure, and Open vSwitch does it in
the flow-miss drop arm of ovs_dp_process_packet(), so nothing is lost by
dropping it here.

On Open vSwitch's OVS_ACTION_ATTR_USERSPACE path the skb is not freed on
this error: do_execute_actions() ignores output_userspace()'s return
value and, unless the upcall was the last action, keeps forwarding the
same skb through the flow's remaining actions. The uarg is completed
while that skb is still in flight, telling the producer its buffers are
free, and SKBFL_SHARED_FRAG is cleared on an skb the rest of the stack
still handles. That flag is what makes esp_input() call skb_cow_data()
instead of decrypting in place, so a later local ESP delivery can
decrypt over frags the skb does not own privately.

Leave error reporting to the callers.
Published: 2026-09-16
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Kernel memory corruption potentially enabling remote code execution or privilege escalation
Action: Immediate Patch
AI Analysis

Impact

The kernel helper skb_zerocopy() copies data from one socket buffer to another. If the fragment copy fails, the helper mistakenly calls skb_tx_error() on the original buffer, destroying it and clearing the SKBFL_SHARED_FRAG flag. This out‑of‑scope free results in a Use‑After‑Free condition (CWE‑416). In paths utilized by Open vSwitch, the packet is not immediately dropped, which causes subsequent processing to reference the freed buffer. That can lead to memory corruption, enabling an attacker to execute code or cause denial of service through carefully crafted network traffic that triggers the fragment copy failure.

Affected Systems

All versions of the Linux kernel shipped before the patch are affected, including any installation that uses Open vSwitch in the OVS_ACTION_ATTR_USERSPACE path. The specific patch commits referenced in the advisory remove the skb_tx_error call from skb_zerocopy() and should be applied to secure the system.

Risk and Exploitability

The CVSS score of 9.3 reflects a high‑severity risk of remote code execution or privilege escalation. The EPSS score of <1% indicates a low probability of exploitation in the wild at the time of assessment, but the impact remains severe and the vulnerability is not listed in the CISA KEV catalog. Attackers would likely need to craft network traffic that triggers a fragment copy failure in the kernel, for example by sending malformed packets to a host running Open vSwitch. Based on the description, the likely attack vector is network‑bound through the kernel’s packet processing path; the probability of successful exploitation remains low, but the potential damage is significant.

Generated by OpenCVE AI on September 18, 2026 at 07:19 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes the fix for skb_zerocopy() (commit 04dd250a78e268af3e7124beb1dc10ec1dd88d60 and related commits).
  • If using Open vSwitch, update to the latest stable release that incorporates the kernel patch, or disable the OVS_ACTION_ATTR_USERSPACE path until the kernel is updated.
  • In the interim, monitor network traffic for abnormal packet patterns and consider blocking traffic that could trigger the fragment copy failure.

Generated by OpenCVE AI on September 18, 2026 at 07:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Fri, 18 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: net: skbuff: don't skb_tx_error() the source skb in skb_zerocopy() skb_zerocopy() copies frags from @from into @to. On an skb_orphan_frags() failure it calls skb_tx_error(@from), a destructive operation on the source skb the copy helper does not own. That completes @from's zerocopy uarg and clears SKBFL_ALL_ZEROCOPY, including the SKBFL_SHARED_FRAG page-ownership marker. Both callers already report the failure on their own drop path. nfnetlink_queue does it at nla_put_failure, and Open vSwitch does it in the flow-miss drop arm of ovs_dp_process_packet(), so nothing is lost by dropping it here. On Open vSwitch's OVS_ACTION_ATTR_USERSPACE path the skb is not freed on this error: do_execute_actions() ignores output_userspace()'s return value and, unless the upcall was the last action, keeps forwarding the same skb through the flow's remaining actions. The uarg is completed while that skb is still in flight, telling the producer its buffers are free, and SKBFL_SHARED_FRAG is cleared on an skb the rest of the stack still handles. That flag is what makes esp_input() call skb_cow_data() instead of decrypting in place, so a later local ESP delivery can decrypt over frags the skb does not own privately. Leave error reporting to the callers.
Title net: skbuff: don't skb_tx_error() the source skb in skb_zerocopy()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T14:42:05.924Z

Reserved: 2026-09-11T19:38:34.783Z

Link: CVE-2026-90049

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:17:18.263

Modified: 2026-09-28T23:10:00.143

Link: CVE-2026-90049

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T07:30:05Z

Weaknesses