7.8
CVE-2026-89487
- EPSS 0.13%
- Veröffentlicht 11.09.2026 19:43:40
- Zuletzt bearbeitet 14.09.2026 13:19:05
- Erkennungen
openvswitch: only skb_tx_error() a packet we are about to drop
In the Linux kernel, the following vulnerability has been resolved:
openvswitch: only skb_tx_error() a packet we are about to drop
queue_userspace_packet() borrows the packet skb -- it only copies it into
a private netlink message (user_skb) and does not own it; on return
do_execute_actions() keeps forwarding it through the flow's remaining
actions. Its error path nevertheless calls skb_tx_error(skb), which via
skb_zcopy_clear() does skb_shinfo(skb)->flags &= ~SKBFL_ALL_ZEROCOPY,
stripping SKBFL_SHARED_FRAG from that live skb (skb_tx_error()'s kerneldoc
says "skb must be freed afterwards").
For a MSG_ZEROCOPY skb carrying page-cache frags, SKBFL_SHARED_FRAG is
what makes esp_input() skb_cow_data() before in-place AEAD; once it is
stripped a later local ESP-in-UDP delivery decrypts in place over pages
the sender does not own -- an unprivileged page-cache write (the
"Fragnesia" primitive).
do_execute_actions() ignores output_userspace()'s return value, so any
action after a failed USERSPACE upcall inherits the stripped skb.
Move the skb_tx_error() to the flow-miss drop path - the "default"
branch of ovs_dp_process_packet()'s switch(error), before kfree_skb().
The call has been here since commit 36d5fe6a0007 ("core, nfqueue,
openvswitch: Orphan frags in skb_zerocopy and handle errors") but was
harmless until esp_input() began relying on SKBFL_SHARED_FRAG to gate
in-place decrypt; only then did stripping it on a still-forwarded skb
become a page-cache write primitive.Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
36d5fe6a000790f56039afe26834265db0a3ad4c
Version <
5de5d554141a15b3f1f5c978fd9f7f4fd6d0600a
Status
affected
Version
36d5fe6a000790f56039afe26834265db0a3ad4c
Version <
48db11e115d1b232edc5591604adc6eda95cd545
Status
affected
Version
36d5fe6a000790f56039afe26834265db0a3ad4c
Version <
4477222e2916a18e273edc139c955ade6bbb7a69
Status
affected
Version
36d5fe6a000790f56039afe26834265db0a3ad4c
Version <
4d5c460ef8754be1d43b16dbf02695b008b207d6
Status
affected
Version
36d5fe6a000790f56039afe26834265db0a3ad4c
Version <
6767d70cf46f65807a6a4c4406a518e6c12e36ae
Status
affected
Version
36d5fe6a000790f56039afe26834265db0a3ad4c
Version <
e41a59fc056f63a7a1f42788913c53cc48d744aa
Status
affected
Version
36d5fe6a000790f56039afe26834265db0a3ad4c
Version <
5d85eef222cfd28e73deed7402c100229e8b9e6e
Status
affected
Version
36d5fe6a000790f56039afe26834265db0a3ad4c
Version <
0dbc2398fca3bb33eda963849f865ddb1b3aa05e
Status
affected
Version
c5f0c0e7525443add533495e93ba8de6feab2396
Status
affected
Version
1674b4bf3eea3cac51b70778e89f8025f7cfe695
Status
affected
Version
3.10.51
Version <
3.11
Status
affected
Version
3.12.40
Version <
3.13
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
3.14
Status
affected
Version
0
Version <
3.14
Status
unaffected
Version <=
5.10.*
Version
5.10.270
Status
unaffected
Version <=
5.15.*
Version
5.15.221
Status
unaffected
Version <=
6.1.*
Version
6.1.188
Status
unaffected
Version <=
6.6.*
Version
6.6.157
Status
unaffected
Version <=
6.12.*
Version
6.12.109
Status
unaffected
Version <=
6.18.*
Version
6.18.50
Status
unaffected
Version <=
7.2.*
Version
7.2.4
Status
unaffected
Version <=
*
Version
7.3-rc1
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.13% | 0.028 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
https://git.kernel.org/stable/c/6767d70cf46f65807a6a4c4406a518e6c12e36ae
https://git.kernel.org/stable/c/e41a59fc056f63a7a1f42788913c53cc48d744aa
https://git.kernel.org/stable/c/5d85eef222cfd28e73deed7402c100229e8b9e6e
https://git.kernel.org/stable/c/0dbc2398fca3bb33eda963849f865ddb1b3aa05e
https://git.kernel.org/stable/c/4477222e2916a18e273edc139c955ade6bbb7a69
https://git.kernel.org/stable/c/48db11e115d1b232edc5591604adc6eda95cd545
https://git.kernel.org/stable/c/4d5c460ef8754be1d43b16dbf02695b008b207d6
https://git.kernel.org/stable/c/5de5d554141a15b3f1f5c978fd9f7f4fd6d0600a