Description
In the Linux kernel, the following vulnerability has been resolved:

xsk: fix NULL pointer dereference in __xsk_rcv()

In the __xsk_rcv() multi-buffer path, xsk_buff_alloc() is called in a
loop without checking its return value. xsk_buff_can_alloc() only
counts fill queue entries without validating their addresses, so it
can succeed while xsk_buff_alloc() rejects all remaining entries and
returns NULL.

Oops: general protection fault, probably for non-canonical address
0xdffffc0000000000
KASAN: null-ptr-deref in range
[0x0000000000000000-0x0000000000000007]
RIP: 0010:__xsk_rcv+0x426/0xc20 (net/xdp/xsk.c:350)
Call Trace:
xsk_generic_rcv+0x26d/0x5f0
xdp_do_generic_redirect+0x3c5/0xcf0
do_xdp_generic+0x92f/0xe70
__netif_receive_skb_core.constprop.0+0xf7e/0x2b30

Fix this with a two-stage transaction. First allocate and stage all
buffers required for the packet, recycling all staged buffers with
xsk_buff_free() if any allocation fails. Only after this stage
succeeds, copy the data, reserve the RX descriptors, and release the
buffers in an error-free loop.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

The Linux kernel contains a NULL pointer dereference in the __xsk_rcv() function when processing XDP socket buffers. When an attacker sends specially crafted traffic or triggers the XDP path repeatedly while the buffer allocator fails, the kernel dereferences a NULL pointer, causing a general protection fault and an Oops. This results in a kernel crash that brings the affected system down, leading to a denial of service. The bug is a classic NULL pointer dereference weakness (CWE‑476).

Affected Systems

All Linux kernel installations that do not yet contain the commit that patches __xsk_rcv() are at risk. The fix has been committed to the mainline kernel; the advisory does not list specific affected versions, so any kernel prior to the inclusion of the patch should be considered vulnerable.

Risk and Exploitability

The attack vector occurs over the network via XDP sockets; a malicious user could send packets that exercise the failing allocation loop to trigger the crash. Although the EPSS score is below 1%, indicating a low likelihood of widespread exploitation, and the vulnerability is not listed in the CISA KEV catalog, a successful exploit would cause an immediate service disruption. The vulnerability does not permit remote code execution; the primary risk is to system availability.

Generated by OpenCVE AI on September 18, 2026 at 22:35 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the kernel to a release that includes the patched __xsk_rcv() implementation, ensuring that XDP socket support (xsk) is built into the kernel.
  • If an immediate kernel update is not feasible, disable XDP socket support and any XDP redirection paths on affected interfaces until the patch is applied to prevent execution of the vulnerable code path.
  • Monitor system logs for Oops or kernel crash messages and verify that the patch has prevented further crashes.

Generated by OpenCVE AI on September 18, 2026 at 22:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Fri, 18 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: xsk: fix NULL pointer dereference in __xsk_rcv() In the __xsk_rcv() multi-buffer path, xsk_buff_alloc() is called in a loop without checking its return value. xsk_buff_can_alloc() only counts fill queue entries without validating their addresses, so it can succeed while xsk_buff_alloc() rejects all remaining entries and returns NULL. Oops: general protection fault, probably for non-canonical address 0xdffffc0000000000 KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007] RIP: 0010:__xsk_rcv+0x426/0xc20 (net/xdp/xsk.c:350) Call Trace: xsk_generic_rcv+0x26d/0x5f0 xdp_do_generic_redirect+0x3c5/0xcf0 do_xdp_generic+0x92f/0xe70 __netif_receive_skb_core.constprop.0+0xf7e/0x2b30 Fix this with a two-stage transaction. First allocate and stage all buffers required for the packet, recycling all staged buffers with xsk_buff_free() if any allocation fails. Only after this stage succeeds, copy the data, reserve the RX descriptors, and release the buffers in an error-free loop.
Title xsk: fix NULL pointer dereference in __xsk_rcv()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:06:21.376Z

Reserved: 2026-09-11T19:38:34.787Z

Link: CVE-2026-90115

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:03.623

Modified: 2026-09-17T17:17:03.623

Link: CVE-2026-90115

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T22:45:15Z

Weaknesses