CVE-2026-90115
In the Linux kernel, the following vulnerability has been resolved:
xsk: fix NULL pointer dereference in __xsk_rcv()
In the __xsk_rcv() multi-buffer path, xsk_buff_alloc() is called in a loop without checking its return value. xsk_buff_can_alloc() only counts fill queue entries without validating their addresses, so it can succeed while xsk_buff_alloc() rejects all remaining entries and returns NULL.
Fix this with a two-stage transaction. First allocate and stage all buffers required for the packet, recycling all staged buffers with xsk_buff_free() if any allocation fails. Only after this stage succeeds, copy the data, reserve the RX descriptors, and release the buffers in an error-free loop.
Detalles técnicos trazas, registros y código del informe original
Oops: general protection fault, probably for non-canonical address 0xdffffc0000000000 KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007] RIP: 0010:__xsk_rcv+0x426/0xc20 (net/xdp/xsk.c:350) Call Trace: xsk_generic_rcv+0x26d/0x5f0 xdp_do_generic_redirect+0x3c5/0xcf0 do_xdp_generic+0x92f/0xe70 __netif_receive_skb_core.constprop.0+0xf7e/0x2b30
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.21%
- Percentil entre todas las CVEs puntuadas: 10
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/214fb79b0379cb0214905632a2537c0c33f594eb
- https://git.kernel.org/stable/c/60d7d3559ce66e227e195e9463cdfed8077c8659
- https://git.kernel.org/stable/c/8341bd3ff126d85bc8c4ed52eedcaa5b1a65f194
- https://git.kernel.org/stable/c/aaebce297efc3e3dccb98a6ff838cfaa47db08db
- https://git.kernel.org/stable/c/e37b2abca80473e106176e41712a369fd2f72117
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-90115",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "804627751b4281dd95148e7564759145da67855e",
"lessThan": "aaebce297efc3e3dccb98a6ff838cfaa47db08db",
"versionType": "git"
},
{
"status": "affected",
"version": "804627751b4281dd95148e7564759145da67855e",
"lessThan": "60d7d3559ce66e227e195e9463cdfed8077c8659",
"versionType": "git"
},
{
"status": "affected",
"version": "804627751b4281dd95148e7564759145da67855e",
"lessThan": "214fb79b0379cb0214905632a2537c0c33f594eb",
"versionType": "git"
},
{
"status": "affected",
"version": "804627751b4281dd95148e7564759145da67855e",
"lessThan": "8341bd3ff126d85bc8c4ed52eedcaa5b1a65f194",
"versionType": "git"
},
{
"status": "affected",
"version": "804627751b4281dd95148e7564759145da67855e",
"lessThan": "e37b2abca80473e106176e41712a369fd2f72117",
"versionType": "git"
}
],
"programFiles": [
"net/xdp/xsk.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6.6"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "6.6",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.6.157",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.110",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.52",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2.6",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"net/xdp/xsk.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-17T17:17:03.623",
"references": [
{
"url": "https://git.kernel.org/stable/c/214fb79b0379cb0214905632a2537c0c33f594eb",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/60d7d3559ce66e227e195e9463cdfed8077c8659",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/8341bd3ff126d85bc8c4ed52eedcaa5b1a65f194",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/aaebce297efc3e3dccb98a6ff838cfaa47db08db",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/e37b2abca80473e106176e41712a369fd2f72117",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nxsk: fix NULL pointer dereference in __xsk_rcv()\n\nIn the __xsk_rcv() multi-buffer path, xsk_buff_alloc() is called in a\nloop without checking its return value. xsk_buff_can_alloc() only\ncounts fill queue entries without validating their addresses, so it\ncan succeed while xsk_buff_alloc() rejects all remaining entries and\nreturns NULL.\n\n Oops: general protection fault, probably for non-canonical address\n 0xdffffc0000000000\n KASAN: null-ptr-deref in range\n [0x0000000000000000-0x0000000000000007]\n RIP: 0010:__xsk_rcv+0x426/0xc20 (net/xdp/xsk.c:350)\n Call Trace:\n xsk_generic_rcv+0x26d/0x5f0\n xdp_do_generic_redirect+0x3c5/0xcf0\n do_xdp_generic+0x92f/0xe70\n __netif_receive_skb_core.constprop.0+0xf7e/0x2b30\n\nFix this with a two-stage transaction. First allocate and stage all\nbuffers required for the packet, recycling all staged buffers with\nxsk_buff_free() if any allocation fails. Only after this stage\nsucceeds, copy the data, reserve the RX descriptors, and release the\nbuffers in an error-free loop."
}
],
"lastModified": "2026-09-17T17:17:03.623",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}