CVE-2026-90086
In the Linux kernel, the following vulnerability has been resolved:
xsk: honor XDP_TX_METADATA in zero-copy path
The zero-copy path reads TX metadata whenever the UMEM has metadata space, even if the descriptor does not set XDP_TX_METADATA. Pass descriptor options through the metadata helpers and ignore metadata unless the option is set.
This does not fix the existing per-WQE metadata handling for mlx5 MPWQEs. Only the descriptor that starts a session passes through xsk_tx_metadata_request() and configures offload state shared by the batch.
Leer descripción completaMostrar menos
Metadata on descriptors joining an open session is therefore not validated and does not configure its requested offloads. In addition, a non-NULL metadata pointer from such a descriptor is treated as a timestamp completion request even when XDP_TXMD_FLAGS_TIMESTAMP is not set, so its metadata union can be overwritten with an unrequested timestamp. Fixing mixed metadata states within one MPWQE requires a separate change.
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.21%
- Percentil entre todas las CVEs puntuadas: 10
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-90086",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "48eb03dd26304c24f03bdbb9382e89c8564e71df",
"lessThan": "53a5b262d706b572840cbe8feae392538077ee19",
"versionType": "git"
},
{
"status": "affected",
"version": "48eb03dd26304c24f03bdbb9382e89c8564e71df",
"lessThan": "bf9387488d6394845076928c6ca5315ce5d84f54",
"versionType": "git"
},
{
"status": "affected",
"version": "48eb03dd26304c24f03bdbb9382e89c8564e71df",
"lessThan": "a6e4b9a6deb9362ef7a0706c70d674e92fe1411a",
"versionType": "git"
}
],
"programFiles": [
"drivers/net/ethernet/intel/igc/igc_main.c",
"drivers/net/ethernet/mellanox/mlx5/core/en/xsk/tx.c",
"drivers/net/ethernet/stmicro/stmmac/stmmac_main.c",
"include/net/libeth/xsk.h",
"include/net/xdp_sock_drv.h",
"include/net/xsk_buff_pool.h",
"net/xdp/xsk_buff_pool.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6.8"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "6.8",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.18.52",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2.6",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/net/ethernet/intel/igc/igc_main.c",
"drivers/net/ethernet/mellanox/mlx5/core/en/xsk/tx.c",
"drivers/net/ethernet/stmicro/stmmac/stmmac_main.c",
"include/net/libeth/xsk.h",
"include/net/xdp_sock_drv.h",
"include/net/xsk_buff_pool.h",
"net/xdp/xsk_buff_pool.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-17T17:16:58.637",
"references": [
{
"url": "https://git.kernel.org/stable/c/53a5b262d706b572840cbe8feae392538077ee19",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/a6e4b9a6deb9362ef7a0706c70d674e92fe1411a",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/bf9387488d6394845076928c6ca5315ce5d84f54",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nxsk: honor XDP_TX_METADATA in zero-copy path\n\nThe zero-copy path reads TX metadata whenever the UMEM has metadata space,\neven if the descriptor does not set XDP_TX_METADATA. Pass descriptor\noptions through the metadata helpers and ignore metadata unless the option\nis set.\n\nThis does not fix the existing per-WQE metadata handling for mlx5 MPWQEs.\nOnly the descriptor that starts a session passes through\nxsk_tx_metadata_request() and configures offload state shared by the batch.\nMetadata on descriptors joining an open session is therefore not validated\nand does not configure its requested offloads. In addition, a non-NULL\nmetadata pointer from such a descriptor is treated as a timestamp\ncompletion request even when XDP_TXMD_FLAGS_TIMESTAMP is not set, so its\nmetadata union can be overwritten with an unrequested timestamp. Fixing\nmixed metadata states within one MPWQE requires a separate change."
}
],
"lastModified": "2026-09-17T17:16:58.637",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}