« Volver al listado

CVE-2026-43093

Estado: ModificadaAlta (7.8)—

In the Linux kernel, the following vulnerability has been resolved:

xsk: tighten UMEM headroom validation to account for tailroom and min frame

The current headroom validation in xdp_umem_reg() could leave us with insufficient space dedicated to even receive minimum-sized ethernet frame. Furthermore if multi-buffer would come to play then skb_shared_info stored at the end of XSK frame would be corrupted.

HW typically works with 128-aligned sizes so let us provide this value as bare minimum.

Multi-buffer setting is known later in the configuration process so besides accounting for 128 bytes, let us also take care of tailroom space upfront.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vulnerabilidad local (AV:L/PR:L) en el kernel Linux que permite corrupción de memoria (skb_shared_info). Escalada de privilegios (T1068) por fallo de validación. Impactos: manipulación de datos en memoria y potencial DoS por corrupción de estructuras de red.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-43093",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "99e3a236dd43d06c65af0a2ef9cb44306aef6e02",
              "lessThan": "5f123bc278bf4e3283d8606321bebbfd299f4384",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "99e3a236dd43d06c65af0a2ef9cb44306aef6e02",
              "lessThan": "1a6051cd7e3e4c54ff3854a43b638b9292af5e67",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "99e3a236dd43d06c65af0a2ef9cb44306aef6e02",
              "lessThan": "8769708add9eadeea8041a9761771bb715a87104",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "99e3a236dd43d06c65af0a2ef9cb44306aef6e02",
              "lessThan": "a03975beb9f6af0d8ac051e30b2abeabe618414f",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "99e3a236dd43d06c65af0a2ef9cb44306aef6e02",
              "lessThan": "0ec4d3f6e6934deb843b561ae048cd17218e5ad1",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "99e3a236dd43d06c65af0a2ef9cb44306aef6e02",
              "lessThan": "9ea6ba4f3195dcba6e8b3e7b2e748593b7cafb12",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "99e3a236dd43d06c65af0a2ef9cb44306aef6e02",
              "lessThan": "6523bc1b40e69301f24c14338b762af4739d6d39",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "99e3a236dd43d06c65af0a2ef9cb44306aef6e02",
              "lessThan": "a315e022a72d95ef5f1d4e58e903cb492b0ad931",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "ad8fb61c184fe0f8d1e0b5b954d010fb9f94a6ee",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "25c9cdef57488578da21d99eb614b97ffcf6e59f",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "98d3c852e63b49129515dd18c875999efaf8530a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4.19.118",
              "lessThan": "4.20",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "5.4.35",
              "lessThan": "5.5",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "5.6.7",
              "lessThan": "5.7",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "net/xdp/xdp_umem.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.7"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.7",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.258",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.209",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.175",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.136",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.83",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.24",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "6.19.14",
              "versionType": "semver",
              "lessThanOrEqual": "6.19.*"
            },
            {
              "status": "unaffected",
              "version": "7.0",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "net/xdp/xdp_umem.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-05-06T10:16:22.667",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/0ec4d3f6e6934deb843b561ae048cd17218e5ad1",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/1a6051cd7e3e4c54ff3854a43b638b9292af5e67",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/5f123bc278bf4e3283d8606321bebbfd299f4384",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/6523bc1b40e69301f24c14338b762af4739d6d39",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/8769708add9eadeea8041a9761771bb715a87104",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/9ea6ba4f3195dcba6e8b3e7b2e748593b7cafb12",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/a03975beb9f6af0d8ac051e30b2abeabe618414f",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/a315e022a72d95ef5f1d4e58e903cb492b0ad931",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nxsk: tighten UMEM headroom validation to account for tailroom and min frame\n\nThe current headroom validation in xdp_umem_reg() could leave us with\ninsufficient space dedicated to even receive minimum-sized ethernet\nframe. Furthermore if multi-buffer would come to play then\nskb_shared_info stored at the end of XSK frame would be corrupted.\n\nHW typically works with 128-aligned sizes so let us provide this value\nas bare minimum.\n\nMulti-buffer setting is known later in the configuration process so\nbesides accounting for 128 bytes, let us also take care of tailroom space\nupfront."
    }
  ],
  "lastModified": "2026-06-17T10:48:55.390",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C1D66A78-E0DD-4D66-9446-03DE28F5FE2F",
              "versionEndExcluding": "4.20",
              "versionStartIncluding": "4.19.118"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4ED55BB9-F8CA-4CCD-94DD-BC6F5E60E5D9",
              "versionEndExcluding": "5.5",
              "versionStartIncluding": "5.4.35"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "30A44027-1F59-4AF5-B227-86E61A43A865",
              "versionEndExcluding": "5.7",
              "versionStartIncluding": "5.6.7"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1D0E985F-975A-4107-B163-94D4DCD5FD9B",
              "versionEndExcluding": "6.6.136",
              "versionStartIncluding": "5.7.1"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7F0AE5B5-23AC-4DCC-B37A-51CA1DAE7BA8",
              "versionEndExcluding": "6.12.83",
              "versionStartIncluding": "6.7"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8126B8B8-6D0B-4443-86C1-672AEE893555",
              "versionEndExcluding": "6.18.24",
              "versionStartIncluding": "6.13"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D6A8A074-BBF4-4803-ABED-519A839435BB",
              "versionEndExcluding": "6.19.14",
              "versionStartIncluding": "6.19"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:5.7:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3D23CE42-BDB2-4216-8495-230ABE98FCDD"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:5.7:rc2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2AAE09B2-58C0-42B8-ACDA-578904723270"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:5.7:rc3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "59EEFC0E-2E5A-4113-A58D-2EE2CC7CFA3B"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:5.7:rc4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3CC0A9A2-D528-49AA-AB7F-37C5EA7AB76D"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:5.7:rc5:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "512FF86F-0B8C-4DEB-9041-8BD384DD2E58"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:5.7:rc6:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F1AB4A11-C03C-4ABB-B596-0EB3B0F1A8DF"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:5.7:rc7:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9D26AE9C-D49F-4FE9-8A6A-5A7199B7436E"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:7.0:rc1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F253B622-8837-4245-BCE5-A7BF8FC76A16"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:7.0:rc2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4AE85AD8-4641-4E7C-A2F4-305E2CD9EE64"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:7.0:rc3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F666C8D8-6538-46D4-B318-87610DE64C34"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:7.0:rc4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "02259FDA-961B-47BC-AE7F-93D7EC6E90C2"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:7.0:rc5:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "58A9FEFF-C040-420D-8F0A-BFDAAA1DF258"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:7.0:rc6:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1D2315C0-D46F-4F85-9754-F9E5E11374A6"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:7.0:rc7:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "512EE3A8-A590-4501-9A94-5D4B268D6138"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}