Description
In the Linux kernel, the following vulnerability has been resolved:

esp: do not unref managed frag pages in esp_ssg_unref()

esp_ssg_unref() releases the page references held on the source
scatterlist after the AEAD operation completes. It calls
skb_page_unref() on every frag page for an out-of-place transform
(req->src != req->dst), and in the error path of esp_output_tail()
(already_unref == true) on the request's own scatterlist.

This is wrong when the skb carries managed frags
(SKBFL_MANAGED_FRAG_REFS). Managed frags are owned by a zerocopy ubuf
and the skb does not hold a per-frag page reference; io_uring SEND_ZC
with a registered buffer attaches the bvec pages this way via
io_sg_from_iter(). The rest of the stack honours this invariant:
skb_release_data() skips the per-frag unref when SKBFL_MANAGED_FRAG_REFS
is set, and skb_zcopy_managed() is the guard used at the other unref
sites.

esp_ssg_unref() is missing that guard, so for a managed-frag skb it
drops a page reference the skb never acquired. This can underflow the
page reference count and free a page that is still in use.

Guard the function with skb_zcopy_managed() so both unref paths are
skipped for managed-frag skbs, matching skb_release_data().
Published: 2026-09-17
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Memory corruption or potential code execution via use‑after‑free of a kernel page
Action: Apply Patch
AI Analysis

Impact

The function esp_ssg_unref() in the Linux kernel incorrectly releases page references on managed fragment SKBs. Because it drops a reference that was never held, the page reference count can underflow, resulting in a kernel page being freed while still in use. This leads to memory corruption and could be escalated to arbitrary code execution if an attacker can supply crafted packets that trigger the faulty paths.

Affected Systems

All Linux kernel releases that include the esp scatterlist handling code are affected, because the vulnerability is in a core networking subsystem. The issue exists until the kernel is patched with the commit that adds the missing guard for SKBFL_MANAGED_FRAG_REFS. No specific vendor or product version is listed, so any distribution using an unpatched kernel is potentially impacted.

Risk and Exploitability

The CVSS score of 7.8 indicates moderate to high severity. The EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog, suggesting that exploitation is currently unlikely. The failure occurs during packet processing, but it is not explicitly stated whether it can be triggered by external traffic. Based on the description, it is inferred that sending crafted network traffic that contains zero‑copy managed fragments could trigger the faulty code path. If an attacker can do so, the low likelihood is outweighed by the high impact of possible kernel memory corruption or code execution.

Generated by OpenCVE AI on September 19, 2026 at 16:00 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the kernel to a version that incorporates the patch implementing the skb_zcopy_managed() guard in esp_ssg_unref().
  • If an immediate kernel upgrade is not feasible, avoid using io_uring SEND_ZC or zero‑copy send paths with registered buffers that produce managed fragment SKBs, thereby eliminating the code path that causes the reference underflow.
  • Continuously monitor kernel logs for OOPS or panics that hint at memory corruption issues linked to ESP processing, and remediate when the kernel is updated.

Generated by OpenCVE AI on September 19, 2026 at 16:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 09:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-415
CWE-416

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: esp: do not unref managed frag pages in esp_ssg_unref() esp_ssg_unref() releases the page references held on the source scatterlist after the AEAD operation completes. It calls skb_page_unref() on every frag page for an out-of-place transform (req->src != req->dst), and in the error path of esp_output_tail() (already_unref == true) on the request's own scatterlist. This is wrong when the skb carries managed frags (SKBFL_MANAGED_FRAG_REFS). Managed frags are owned by a zerocopy ubuf and the skb does not hold a per-frag page reference; io_uring SEND_ZC with a registered buffer attaches the bvec pages this way via io_sg_from_iter(). The rest of the stack honours this invariant: skb_release_data() skips the per-frag unref when SKBFL_MANAGED_FRAG_REFS is set, and skb_zcopy_managed() is the guard used at the other unref sites. esp_ssg_unref() is missing that guard, so for a managed-frag skb it drops a page reference the skb never acquired. This can underflow the page reference count and free a page that is still in use. Guard the function with skb_zcopy_managed() so both unref paths are skipped for managed-frag skbs, matching skb_release_data().
Title esp: do not unref managed frag pages in esp_ssg_unref()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:55:56.276Z

Reserved: 2026-09-17T16:02:15.085Z

Link: CVE-2026-93105

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:04.847

Modified: 2026-09-18T18:18:20.667

Link: CVE-2026-93105

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T16:15:13Z

Weaknesses