« Volver al listado

CVE-2026-90115

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

xsk: fix NULL pointer dereference in __xsk_rcv()

In the __xsk_rcv() multi-buffer path, xsk_buff_alloc() is called in a loop without checking its return value. xsk_buff_can_alloc() only counts fill queue entries without validating their addresses, so it can succeed while xsk_buff_alloc() rejects all remaining entries and returns NULL.

Fix this with a two-stage transaction. First allocate and stage all buffers required for the packet, recycling all staged buffers with xsk_buff_free() if any allocation fails. Only after this stage succeeds, copy the data, reserve the RX descriptors, and release the buffers in an error-free loop.

Detalles técnicos trazas, registros y código del informe original
  Oops: general protection fault, probably for non-canonical address
   0xdffffc0000000000
  KASAN: null-ptr-deref in range
   [0x0000000000000000-0x0000000000000007]
  RIP: 0010:__xsk_rcv+0x426/0xc20 (net/xdp/xsk.c:350)
  Call Trace:
   xsk_generic_rcv+0x26d/0x5f0
   xdp_do_generic_redirect+0x3c5/0xcf0
   do_xdp_generic+0x92f/0xe70
   __netif_receive_skb_core.constprop.0+0xf7e/0x2b30

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-90115",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "804627751b4281dd95148e7564759145da67855e",
              "lessThan": "aaebce297efc3e3dccb98a6ff838cfaa47db08db",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "804627751b4281dd95148e7564759145da67855e",
              "lessThan": "60d7d3559ce66e227e195e9463cdfed8077c8659",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "804627751b4281dd95148e7564759145da67855e",
              "lessThan": "214fb79b0379cb0214905632a2537c0c33f594eb",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "804627751b4281dd95148e7564759145da67855e",
              "lessThan": "8341bd3ff126d85bc8c4ed52eedcaa5b1a65f194",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "804627751b4281dd95148e7564759145da67855e",
              "lessThan": "e37b2abca80473e106176e41712a369fd2f72117",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "net/xdp/xsk.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.6"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.6",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.6.157",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.110",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.52",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "net/xdp/xsk.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-17T17:17:03.623",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/214fb79b0379cb0214905632a2537c0c33f594eb",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/60d7d3559ce66e227e195e9463cdfed8077c8659",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/8341bd3ff126d85bc8c4ed52eedcaa5b1a65f194",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/aaebce297efc3e3dccb98a6ff838cfaa47db08db",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/e37b2abca80473e106176e41712a369fd2f72117",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nxsk: fix NULL pointer dereference in __xsk_rcv()\n\nIn the __xsk_rcv() multi-buffer path, xsk_buff_alloc() is called in a\nloop without checking its return value. xsk_buff_can_alloc() only\ncounts fill queue entries without validating their addresses, so it\ncan succeed while xsk_buff_alloc() rejects all remaining entries and\nreturns NULL.\n\n  Oops: general protection fault, probably for non-canonical address\n   0xdffffc0000000000\n  KASAN: null-ptr-deref in range\n   [0x0000000000000000-0x0000000000000007]\n  RIP: 0010:__xsk_rcv+0x426/0xc20 (net/xdp/xsk.c:350)\n  Call Trace:\n   xsk_generic_rcv+0x26d/0x5f0\n   xdp_do_generic_redirect+0x3c5/0xcf0\n   do_xdp_generic+0x92f/0xe70\n   __netif_receive_skb_core.constprop.0+0xf7e/0x2b30\n\nFix this with a two-stage transaction. First allocate and stage all\nbuffers required for the packet, recycling all staged buffers with\nxsk_buff_free() if any allocation fails. Only after this stage\nsucceeds, copy the data, reserve the RX descriptors, and release the\nbuffers in an error-free loop."
    }
  ],
  "lastModified": "2026-09-17T17:17:03.623",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}