Description
In the Linux kernel, the following vulnerability has been resolved:

xsk: honor XDP_TX_METADATA in zero-copy path

The zero-copy path reads TX metadata whenever the UMEM has metadata space,
even if the descriptor does not set XDP_TX_METADATA. Pass descriptor
options through the metadata helpers and ignore metadata unless the option
is set.

This does not fix the existing per-WQE metadata handling for mlx5 MPWQEs.
Only the descriptor that starts a session passes through
xsk_tx_metadata_request() and configures offload state shared by the batch.
Metadata on descriptors joining an open session is therefore not validated
and does not configure its requested offloads. In addition, a non-NULL
metadata pointer from such a descriptor is treated as a timestamp
completion request even when XDP_TXMD_FLAGS_TIMESTAMP is not set, so its
metadata union can be overwritten with an unrequested timestamp. Fixing
mixed metadata states within one MPWQE requires a separate change.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Potential memory corruption from unvalidated XDP TX metadata handling
Action: Apply patch
AI Analysis

Impact

The Linux kernel’s zero‑copy path for AF_XDP sockets incorrectly treats transmit metadata when the user memory has metadata space, even if a descriptor does not set the XDP_TX_METADATA flag. As a result, the kernel reads and uses metadata that is not explicitly requested, potentially leading to improper offload configuration or overwriting of data such as timestamps when XDP_TXMD_FLAGS_TIMESTAMP is unset. This flaw is an example of CWE‑20 – improper validation of user input, which can allow attackers to influence kernel memory operations and compromise system integrity.

Affected Systems

All Linux kernel releases that employ the AF_XDP zero‑copy path with UMEM metadata support are affected. No specific version range is provided, so any kernel that includes the vulnerable zero‑copy logic without the applied patch is considered at risk. Users running network stacks that rely on XDP sockets need to verify their kernel version.

Risk and Exploitability

The EPSS score being less than 1% suggests a low likelihood of widespread exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. However, the deficiency remains susceptible to malicious manipulation of network traffic and could lead to memory corruption or denial of service if an attacker can craft descriptors that trigger the erroneous metadata handling. The CVSS score is not supplied, but the impact could be high if the flaw is leveraged in an environment with privileged network activity. Patch deployment is recommended even though the immediate risk appears modest.

Generated by OpenCVE AI on September 20, 2026 at 03:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update to the latest Linux kernel version that includes the fix for the XDP zero‑copy metadata handling issue.
  • Configure AF_XDP sockets to only use descriptors with the XDP_TX_METADATA flag set and avoid sending metadata when it is not required.
  • Monitor kernel logs for unusual metadata errors or anomalous TMX entries that may indicate attempted exploitation.

Generated by OpenCVE AI on September 20, 2026 at 03:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 03:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: xsk: honor XDP_TX_METADATA in zero-copy path The zero-copy path reads TX metadata whenever the UMEM has metadata space, even if the descriptor does not set XDP_TX_METADATA. Pass descriptor options through the metadata helpers and ignore metadata unless the option is set. This does not fix the existing per-WQE metadata handling for mlx5 MPWQEs. Only the descriptor that starts a session passes through xsk_tx_metadata_request() and configures offload state shared by the batch. Metadata on descriptors joining an open session is therefore not validated and does not configure its requested offloads. In addition, a non-NULL metadata pointer from such a descriptor is treated as a timestamp completion request even when XDP_TXMD_FLAGS_TIMESTAMP is not set, so its metadata union can be overwritten with an unrequested timestamp. Fixing mixed metadata states within one MPWQE requires a separate change.
Title xsk: honor XDP_TX_METADATA in zero-copy path
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:06:02.212Z

Reserved: 2026-09-11T19:38:34.785Z

Link: CVE-2026-90086

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:16:58.637

Modified: 2026-09-17T17:16:58.637

Link: CVE-2026-90086

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T03:30:13Z

Weaknesses
  • CWE-20

    Improper Input Validation