7.8

CVE-2026-89487

openvswitch: only skb_tx_error() a packet we are about to drop

In the Linux kernel, the following vulnerability has been resolved:

openvswitch: only skb_tx_error() a packet we are about to drop

queue_userspace_packet() borrows the packet skb -- it only copies it into
a private netlink message (user_skb) and does not own it; on return
do_execute_actions() keeps forwarding it through the flow's remaining
actions. Its error path nevertheless calls skb_tx_error(skb), which via
skb_zcopy_clear() does skb_shinfo(skb)->flags &= ~SKBFL_ALL_ZEROCOPY,
stripping SKBFL_SHARED_FRAG from that live skb (skb_tx_error()'s kerneldoc
says "skb must be freed afterwards").

For a MSG_ZEROCOPY skb carrying page-cache frags, SKBFL_SHARED_FRAG is
what makes esp_input() skb_cow_data() before in-place AEAD; once it is
stripped a later local ESP-in-UDP delivery decrypts in place over pages
the sender does not own -- an unprivileged page-cache write (the
"Fragnesia" primitive).
do_execute_actions() ignores output_userspace()'s return value, so any
action after a failed USERSPACE upcall inherits the stripped skb.

Move the skb_tx_error() to the flow-miss drop path - the "default"
branch of ovs_dp_process_packet()'s switch(error), before kfree_skb().

The call has been here since commit 36d5fe6a0007 ("core, nfqueue,
openvswitch: Orphan frags in skb_zerocopy and handle errors") but was
harmless until esp_input() began relying on SKBFL_SHARED_FRAG to gate
in-place decrypt; only then did stripping it on a still-forwarded skb
become a page-cache write primitive.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 36d5fe6a000790f56039afe26834265db0a3ad4c
Version < 5de5d554141a15b3f1f5c978fd9f7f4fd6d0600a
Status affected
Version 36d5fe6a000790f56039afe26834265db0a3ad4c
Version < 48db11e115d1b232edc5591604adc6eda95cd545
Status affected
Version 36d5fe6a000790f56039afe26834265db0a3ad4c
Version < 4477222e2916a18e273edc139c955ade6bbb7a69
Status affected
Version 36d5fe6a000790f56039afe26834265db0a3ad4c
Version < 4d5c460ef8754be1d43b16dbf02695b008b207d6
Status affected
Version 36d5fe6a000790f56039afe26834265db0a3ad4c
Version < 6767d70cf46f65807a6a4c4406a518e6c12e36ae
Status affected
Version 36d5fe6a000790f56039afe26834265db0a3ad4c
Version < e41a59fc056f63a7a1f42788913c53cc48d744aa
Status affected
Version 36d5fe6a000790f56039afe26834265db0a3ad4c
Version < 5d85eef222cfd28e73deed7402c100229e8b9e6e
Status affected
Version 36d5fe6a000790f56039afe26834265db0a3ad4c
Version < 0dbc2398fca3bb33eda963849f865ddb1b3aa05e
Status affected
Version c5f0c0e7525443add533495e93ba8de6feab2396
Status affected
Version 1674b4bf3eea3cac51b70778e89f8025f7cfe695
Status affected
Version 3.10.51
Version < 3.11
Status affected
Version 3.12.40
Version < 3.13
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 3.14
Status affected
Version 0
Version < 3.14
Status unaffected
Version <= 5.10.*
Version 5.10.270
Status unaffected
Version <= 5.15.*
Version 5.15.221
Status unaffected
Version <= 6.1.*
Version 6.1.188
Status unaffected
Version <= 6.6.*
Version 6.6.157
Status unaffected
Version <= 6.12.*
Version 6.12.109
Status unaffected
Version <= 6.18.*
Version 6.18.50
Status unaffected
Version <= 7.2.*
Version 7.2.4
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.13% 0.028
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/6767d70cf46f65807a6a4c4406a518e6c12e36ae
https://git.kernel.org/stable/c/e41a59fc056f63a7a1f42788913c53cc48d744aa
https://git.kernel.org/stable/c/5d85eef222cfd28e73deed7402c100229e8b9e6e
https://git.kernel.org/stable/c/0dbc2398fca3bb33eda963849f865ddb1b3aa05e
https://git.kernel.org/stable/c/4477222e2916a18e273edc139c955ade6bbb7a69
https://git.kernel.org/stable/c/48db11e115d1b232edc5591604adc6eda95cd545
https://git.kernel.org/stable/c/4d5c460ef8754be1d43b16dbf02695b008b207d6
https://git.kernel.org/stable/c/5de5d554141a15b3f1f5c978fd9f7f4fd6d0600a