7.8

CVE-2026-98368

esp: downgrade zerocopy managed frags before mutating skb frags

In the Linux kernel, the following vulnerability has been resolved:

esp: downgrade zerocopy managed frags before mutating skb frags

On the out-of-place output path (esp->inplace == false) ESP rewrites the
skb frag array: esp_output_head() appends a trailer frag and
esp_output_tail() replaces the frags with a destination page, both
referenced with get_page().

When the skb carries zerocopy managed frags (SKBFL_MANAGED_FRAG_REFS) the
payload frags are owned by the ubuf and must not be referenced or
unreferenced individually, but ESP mutates the frag array without ever
downgrading the skb.  This breaks the managed-frag invariant two ways:

  - esp_ssg_unref() walks the source scatterlist and drops a page
    reference for every frag, including the ubuf-owned payload frags,
    pushing their refcount below the GUP pin bias while the pages are
    still pinned, i.e. a use-after-free of the zerocopy pages;

  - esp_output_tail() installs its destination page as frag 0 with
    get_page() but leaves SKBFL_MANAGED_FRAG_REFS set, so
    skb_release_data() takes the skip_unref branch and never drops that
    reference, leaking the x->xfrag page at packet rate.

Fix this the way every other frag-mutating site does (__ip_append_data(),
__ip6_append_data(), tcp_sendmsg_locked()) and call
skb_zcopy_downgrade_managed() before ESP touches the frag array: it takes
a real reference on each existing frag and clears SKBFL_MANAGED_FRAG_REFS,
so the per-frag unref in esp_ssg_unref() and the frag release in
skb_release_data() are both balanced and no mixed-ownership frag array is
left behind.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 753f1ca4e1e50248a1b760c9774d6d6b354562cc
Version < 2359264f377cdbdef2d95868cc8fb572949e48d3
Status affected
Version 753f1ca4e1e50248a1b760c9774d6d6b354562cc
Version < 69a768c12398cada8528080332c822623fa7064d
Status affected
Version 753f1ca4e1e50248a1b760c9774d6d6b354562cc
Version < 6508304ac2c8cdafca2f4ab915df8c707893e134
Status affected
Version 753f1ca4e1e50248a1b760c9774d6d6b354562cc
Version < 6cab554f2c0f28773f712ed3a5479103f42ce844
Status affected
Version 753f1ca4e1e50248a1b760c9774d6d6b354562cc
Version < 0d0845ee61c5df47cc68bc446501f48f71e8dcc6
Status affected
Version 753f1ca4e1e50248a1b760c9774d6d6b354562cc
Version < f89416eb3db151170a6f3c6dfc5239d26cdce4d2
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.0
Status affected
Version 0
Version < 6.0
Status unaffected
Version <= 6.1.*
Version 6.1.189
Status unaffected
Version <= 6.6.*
Version 6.6.158
Status unaffected
Version <= 6.12.*
Version 6.12.112
Status unaffected
Version <= 6.18.*
Version 6.18.54
Status unaffected
Version <= 7.2.*
Version 7.2.8
Status unaffected
Version <= *
Version 7.3-rc4
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.13% 0.02
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/2359264f377cdbdef2d95868cc8fb572949e48d3
https://git.kernel.org/stable/c/69a768c12398cada8528080332c822623fa7064d
https://git.kernel.org/stable/c/6508304ac2c8cdafca2f4ab915df8c707893e134
https://git.kernel.org/stable/c/6cab554f2c0f28773f712ed3a5479103f42ce844
https://git.kernel.org/stable/c/0d0845ee61c5df47cc68bc446501f48f71e8dcc6
https://git.kernel.org/stable/c/f89416eb3db151170a6f3c6dfc5239d26cdce4d2