Description
In the Linux kernel, the following vulnerability has been resolved:

virtio_net: Fix resize of the RX ring

When a AF_XDP socket is attached, the virtnet_rx_resize
should resize the rq->xsk_buffs XSK buffer array. Otherwise,
when the size grows, the virtnet_rx_resume() causes a write
past the end of the array. This is easily reproducable with

ethtool -G ens3 rx 32
./xdpsock -i eth0 -q 0 -r -z &
ethtool -G eth0 rx 256
Published: 2026-09-17
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Patch Kernel
AI Analysis

Impact

A flaw in the Linux kernel’s virtio_net driver causes the RX ring buffer array to be resized incorrectly when an AF_XDP socket is attached. The driver writes past the end of the XSK buffer array, creating an out‑of‑bounds write. This buffer overflow can corrupt kernel memory, leading to a crash or, if an attacker controls the data that triggers the resize, the possibility of executing arbitrary code on the host.

Affected Systems

All Linux kernel installations that include the virtio_net driver and employ AF_XDP sockets are affected. The issue applies to any kernel version built with the vulnerable virtio_net implementation, regardless of distribution, until the patch that fixes the resize logic is applied.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity flaw, but the EPSS score is below 1%, showing a very low probability of real‑world exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves an attacker manipulating XSK buffer sizes or initiating an AF_XDP socket on a system exposed to untrusted traffic, which could trigger the vulnerable resize path. Based on the description, it is inferred that an attacker could cause kernel memory corruption, potentially leading to a crash or remote code execution.

Generated by OpenCVE AI on September 20, 2026 at 05:58 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes the virtio_net resize bug fix, such as the latest stable release from the vendor’s repository.
  • If a kernel upgrade is not immediately possible, disable or limit the use of AF_XDP sockets to prevent the vulnerable resize path from being exercised.
  • Monitor system logs and kernel dumps for signs of out‑of‑bounds writes or unexpected crashes, and investigate any incidents promptly.

Generated by OpenCVE AI on September 20, 2026 at 05:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119

Sun, 20 Sep 2026 04:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119

Sat, 19 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: virtio_net: Fix resize of the RX ring When a AF_XDP socket is attached, the virtnet_rx_resize should resize the rq->xsk_buffs XSK buffer array. Otherwise, when the size grows, the virtnet_rx_resume() causes a write past the end of the array. This is easily reproducable with ethtool -G ens3 rx 32 ./xdpsock -i eth0 -q 0 -r -z & ethtool -G eth0 rx 256
Title virtio_net: Fix resize of the RX ring
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:53:19.794Z

Reserved: 2026-09-11T19:38:34.789Z

Link: CVE-2026-90142

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:06.990

Modified: 2026-09-18T18:17:43.567

Link: CVE-2026-90142

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T06:00:14Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer