Description
In the Linux kernel, the following vulnerability has been resolved:

tcp: reject non zerocopy devmem tx

Devmem tcp tx doesn't work without zero-copy, however it's not currently
enforced if NETIF_F_SG isn't present. In this case, tcp_sendmsg_locked()
will try the copy path and try to copy data from an iovec which consists
of offsets into the dma-buf and would normally fail. Moreover,
d9c56501c72fd ("net: tcp: block mixing readable and unreadable frags")
relies on that and assumes that the devmem binding is present IFF we're
using the zero-copy path, which can be used to mix net-iov and pages in
a single skb, and break invariants. Let's reject devmem tx without
zero-copy.

Note, the parameter check the patch is modifying is too loose, we can
create an io_uring request with dmabuf_id and all ZC flags, but which
won't have the binding. We replace it with stricter validation.
Published: 2026-09-17
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Potential for data corruption and kernel instability
Action: Apply Patch
AI Analysis

Impact

The vulnerability allows non‑zero‑copy devmem TCP transmissions when the NETIF_F_SG flag is absent, causing the kernel to attempt a copy operation on an iovec that references a dmabuf. This can lead to copy failures or violate internal invariants that separate readable and unreadable fragments, potentially resulting in memory corruption or kernel instability. The issue stems from a weakness in input validation (CWE-20). The patch tightens parameter validation to reject devmem traffic that does not meet zero‑copy requirements, thereby restoring the intended separation of network fragments.

Affected Systems

All Linux kernel releases that include the tcp devmem handling code prior to the patch; the issue is present in any kernel built from the source specified in the referenced commits and does not affect other kernel subsystems. It impacts network interfaces that may use devmem bindings and the NETIF_F_SG flag.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity vulnerability, but the EPSS score of less than 1% and lack of listing in the CISA KEV catalog suggest a very low likelihood of exploitation. However, if an attacker can craft packets that trigger non‑zero‑copy devmem outbound traffic—either through local privilege or remote network connections—they could destabilize the kernel or corrupt data buffers. The attack vector is inferred to be network‑based, requiring the ability to send large or specially formatted TCP segments that invoke the devmem path.

Generated by OpenCVE AI on September 20, 2026 at 04:52 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes the commit(s) fixing the devmem zero‑copy enforcement, as listed in the referenced kernel patches.
  • Rebuild or install a kernel build that incorporates the patches shown in the Git commits 125755776bc6d4dd53eaf551c87e3d460625d638, 2151b2bcf6fcec52665f606eed20da068447f0b7, or b04326c7927af7048fd4e730f5770cca350d0a60.
  • Alternatively, configure network interfaces to ensure the NETIF_F_SG flag is enabled or disable devmem usage altogether to prevent the exploit path.

Generated by OpenCVE AI on September 20, 2026 at 04:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 05:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: tcp: reject non zerocopy devmem tx Devmem tcp tx doesn't work without zero-copy, however it's not currently enforced if NETIF_F_SG isn't present. In this case, tcp_sendmsg_locked() will try the copy path and try to copy data from an iovec which consists of offsets into the dma-buf and would normally fail. Moreover, d9c56501c72fd ("net: tcp: block mixing readable and unreadable frags") relies on that and assumes that the devmem binding is present IFF we're using the zero-copy path, which can be used to mix net-iov and pages in a single skb, and break invariants. Let's reject devmem tx without zero-copy. Note, the parameter check the patch is modifying is too loose, we can create an io_uring request with dmabuf_id and all ZC flags, but which won't have the binding. We replace it with stricter validation.
Title tcp: reject non zerocopy devmem tx
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:52:45.227Z

Reserved: 2026-09-11T19:38:34.783Z

Link: CVE-2026-90051

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:16:53.490

Modified: 2026-09-18T18:17:39.777

Link: CVE-2026-90051

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T05:00:13Z

Weaknesses
  • CWE-20

    Improper Input Validation