-

CVE-2026-90086

xsk: honor XDP_TX_METADATA in zero-copy path

In the Linux kernel, the following vulnerability has been resolved:

xsk: honor XDP_TX_METADATA in zero-copy path

The zero-copy path reads TX metadata whenever the UMEM has metadata space,
even if the descriptor does not set XDP_TX_METADATA. Pass descriptor
options through the metadata helpers and ignore metadata unless the option
is set.

This does not fix the existing per-WQE metadata handling for mlx5 MPWQEs.
Only the descriptor that starts a session passes through
xsk_tx_metadata_request() and configures offload state shared by the batch.
Metadata on descriptors joining an open session is therefore not validated
and does not configure its requested offloads. In addition, a non-NULL
metadata pointer from such a descriptor is treated as a timestamp
completion request even when XDP_TXMD_FLAGS_TIMESTAMP is not set, so its
metadata union can be overwritten with an unrequested timestamp. Fixing
mixed metadata states within one MPWQE requires a separate change.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 48eb03dd26304c24f03bdbb9382e89c8564e71df
Version < 53a5b262d706b572840cbe8feae392538077ee19
Status affected
Version 48eb03dd26304c24f03bdbb9382e89c8564e71df
Version < bf9387488d6394845076928c6ca5315ce5d84f54
Status affected
Version 48eb03dd26304c24f03bdbb9382e89c8564e71df
Version < a6e4b9a6deb9362ef7a0706c70d674e92fe1411a
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.8
Status affected
Version 0
Version < 6.8
Status unaffected
Version <= 6.18.*
Version 6.18.52
Status unaffected
Version <= 7.2.*
Version 7.2.6
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.2% 0.099
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/53a5b262d706b572840cbe8feae392538077ee19
https://git.kernel.org/stable/c/bf9387488d6394845076928c6ca5315ce5d84f54
https://git.kernel.org/stable/c/a6e4b9a6deb9362ef7a0706c70d674e92fe1411a