Description
In the Linux kernel, the following vulnerability has been resolved:

virtio-net: Ensure that TCP packets don't overflow gso_segs

The user can specify any gso_size in a packet crafted with an AF_PACKET
PACKET_VNET_HDR socket, even smaller than TCP_MIN_GSO_SIZE = 8. At the
same time, GSO_MAX_SIZE = 8 * GSO_MAX_SEGS = 8 * 65535. When the user
crafts a packet with gso_size < 8, there is a risk for partial GSO to
overflow the 16-bit gso_segs field when dividing the SKB length by
gso_size.

Adjust gso_size of TCP packets to be at least TCP_MIN_GSO_SIZE = 8. Keep
gso_size of UDP GSO packets, as gso_size=1 is valid and explicitly
tested at tools/testing/selftests/net/tun.c:649.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Kernel memory corruption leading to crash or availability loss
Action: Apply Patch
AI Analysis

Impact

A user can craft a packet with an AF_PACKET PACKET_VNET_HDR socket, setting the gso_size field to any value, even below the required minimum of 8 bytes. The virtio-net driver in the Linux kernel divides the socket buffer length by this gso_size and stores the result in a 16‑bit gso_segs field. When gso_size is less than 8, the division can produce a value larger than 65535, causing the 16‑bit field to overflow and corrupt memory. This overflow can destabilize the kernel and lead to a crash or other malicious behavior such as memory corruption. The vulnerability exists only in the virtio‑net driver and is triggered by malformed TCP packets with an invalid gso_size.

Affected Systems

All Linux kernel versions prior to the commit that validates gso_size in virtio‑net are affected. The issue arises wherever virtio‑net networking is enabled, which is common in virtual machines that use VirtIO devices. Any kernel lacking the fix that enforces a minimum TCP gso_size of 8 is vulnerable; the exact version range is not listed in the data, but the vulnerability affects all kernels before the patch.

Risk and Exploitability

The EPSS score indicates a very low probability of exploitation (<1%). The vulnerability is not listed in CISA KEV. Based on the description, it is inferred that an attacker needs to create an AF_PACKET PACKET_VNET_HDR socket, which typically requires CAP_NET_RAW or root privileges. Thus the exploitation is likely local rather than remote, and the impact would be memory corruption leading to a kernel crash or denial of service.

Generated by OpenCVE AI on September 20, 2026 at 05:11 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the kernel update that includes the commit adding gso_size validation for TCP packets in virtio‑net, ensuring gso_size is at least the minimum required.
  • If an immediate update is not possible, restrict the ability of untrusted users to create AF_PACKET PACKET_VNET_HDR sockets, for example by removing CAP_NET_RAW from those users or applying an SELinux/AppArmor rule to block such socket creation.
  • Configure the system to capture kernel crashes (e.g., enable kdump or core dumping) and monitor logs for GSO‑related anomalies so that any exploitation attempts are detected promptly.

Generated by OpenCVE AI on September 20, 2026 at 05:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 20 Sep 2026 05:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-680

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: virtio-net: Ensure that TCP packets don't overflow gso_segs The user can specify any gso_size in a packet crafted with an AF_PACKET PACKET_VNET_HDR socket, even smaller than TCP_MIN_GSO_SIZE = 8. At the same time, GSO_MAX_SIZE = 8 * GSO_MAX_SEGS = 8 * 65535. When the user crafts a packet with gso_size < 8, there is a risk for partial GSO to overflow the 16-bit gso_segs field when dividing the SKB length by gso_size. Adjust gso_size of TCP packets to be at least TCP_MIN_GSO_SIZE = 8. Keep gso_size of UDP GSO packets, as gso_size=1 is valid and explicitly tested at tools/testing/selftests/net/tun.c:649.
Title virtio-net: Ensure that TCP packets don't overflow gso_segs
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:05:46.968Z

Reserved: 2026-09-11T19:38:34.784Z

Link: CVE-2026-90063

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:16:55.080

Modified: 2026-09-17T17:16:55.080

Link: CVE-2026-90063

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T05:15:16Z

Weaknesses
  • CWE-680

    Integer Overflow to Buffer Overflow