7.8

CVE-2026-43093

xsk: tighten UMEM headroom validation to account for tailroom and min frame

In the Linux kernel, the following vulnerability has been resolved:

xsk: tighten UMEM headroom validation to account for tailroom and min frame

The current headroom validation in xdp_umem_reg() could leave us with
insufficient space dedicated to even receive minimum-sized ethernet
frame. Furthermore if multi-buffer would come to play then
skb_shared_info stored at the end of XSK frame would be corrupted.

HW typically works with 128-aligned sizes so let us provide this value
as bare minimum.

Multi-buffer setting is known later in the configuration process so
besides accounting for 128 bytes, let us also take care of tailroom space
upfront.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version 99e3a236dd43d06c65af0a2ef9cb44306aef6e02
Version < a03975beb9f6af0d8ac051e30b2abeabe618414f
Status affected
Version 99e3a236dd43d06c65af0a2ef9cb44306aef6e02
Version < 0ec4d3f6e6934deb843b561ae048cd17218e5ad1
Status affected
Version 99e3a236dd43d06c65af0a2ef9cb44306aef6e02
Version < 9ea6ba4f3195dcba6e8b3e7b2e748593b7cafb12
Status affected
Version 99e3a236dd43d06c65af0a2ef9cb44306aef6e02
Version < 6523bc1b40e69301f24c14338b762af4739d6d39
Status affected
Version 99e3a236dd43d06c65af0a2ef9cb44306aef6e02
Version < a315e022a72d95ef5f1d4e58e903cb492b0ad931
Status affected
Version ad8fb61c184fe0f8d1e0b5b954d010fb9f94a6ee
Status affected
Version 25c9cdef57488578da21d99eb614b97ffcf6e59f
Status affected
Version 98d3c852e63b49129515dd18c875999efaf8530a
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 5.7
Status affected
Version 0
Version < 5.7
Status unaffected
Version <= 6.6.*
Version 6.6.136
Status unaffected
Version <= 6.12.*
Version 6.12.83
Status unaffected
Version <= 6.18.*
Version 6.18.24
Status unaffected
Version <= 6.19.*
Version 6.19.14
Status unaffected
Version <= *
Version 7.0
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.01% 0.024
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.