CVE-2026-53215
In the Linux kernel, the following vulnerability has been resolved:
net: mvpp2: refill RX buffers before XDP or skb use
The RX error path returns the current descriptor buffer to the hardware BM pool. That is only valid while the driver still owns the buffer.
mvpp2_rx_refill() can fail after the current buffer has been handed to XDP or attached to an skb. In those cases mvpp2_run_xdp() may have recycled, redirected, or queued the page for XDP_TX, and an skb free also retires the data buffer. Returning such a buffer to BM lets hardware DMA into memory that is no longer owned by the RX ring.
Refill the BM pool before handing the current buffer to XDP or to the skb. If the allocation fails there, drop the packet and return the still-owned current buffer to BM, preserving the pool depth.
Leer descripción completaMostrar menos
Once the refill succeeds, later local drops retire/free the current buffer instead of returning it to BM.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 9.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.74%
- Percentil entre todas las CVEs puntuadas: 53
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1190Exploit Public-Facing Applicationinitial access85 % - Impacto secundario
T1565.001Stored Data Manipulationimpact70 %
Vector CVSS AV:N/AC:L/PR:N: explotación remota sin privilegios (T1190). RX buffer después de XDP permite DMA en memoria no controlada, causando DoS (corrupción/crash) o manipulación de datos en kernel.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
CWE
- NVD-CWE-noinfo
Referencias
- https://git.kernel.org/stable/c/02e1b5c4d3b4c658b72c145427cded1bba613fc1
- https://git.kernel.org/stable/c/580f92f27cb8724bcc4be98ee89890eab524a2ae
- https://git.kernel.org/stable/c/5e8e2a9624df72fca7c736b2966b2cbf6c9c3ff6
- https://git.kernel.org/stable/c/8a2126c5afe89f8ceeb60a3afb9f075b736194cd
- https://git.kernel.org/stable/c/a03cdcedb2cbcc42551dc3e4746929e93c5352d5
- https://git.kernel.org/stable/c/a88b3293b556f4d8fba11db9a8061a6b0d3b69e6
- https://git.kernel.org/stable/c/d0c8c4fbd22d260fe28530260656c5fb3c20ce84
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-53215",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Secondary",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "07dd0a7aae7f72af7cec18909581c2bb570edddc",
"lessThan": "a88b3293b556f4d8fba11db9a8061a6b0d3b69e6",
"versionType": "git"
},
{
"status": "affected",
"version": "07dd0a7aae7f72af7cec18909581c2bb570edddc",
"lessThan": "a03cdcedb2cbcc42551dc3e4746929e93c5352d5",
"versionType": "git"
},
{
"status": "affected",
"version": "07dd0a7aae7f72af7cec18909581c2bb570edddc",
"lessThan": "580f92f27cb8724bcc4be98ee89890eab524a2ae",
"versionType": "git"
},
{
"status": "affected",
"version": "07dd0a7aae7f72af7cec18909581c2bb570edddc",
"lessThan": "d0c8c4fbd22d260fe28530260656c5fb3c20ce84",
"versionType": "git"
},
{
"status": "affected",
"version": "07dd0a7aae7f72af7cec18909581c2bb570edddc",
"lessThan": "8a2126c5afe89f8ceeb60a3afb9f075b736194cd",
"versionType": "git"
},
{
"status": "affected",
"version": "07dd0a7aae7f72af7cec18909581c2bb570edddc",
"lessThan": "02e1b5c4d3b4c658b72c145427cded1bba613fc1",
"versionType": "git"
},
{
"status": "affected",
"version": "07dd0a7aae7f72af7cec18909581c2bb570edddc",
"lessThan": "5e8e2a9624df72fca7c736b2966b2cbf6c9c3ff6",
"versionType": "git"
},
{
"status": "affected",
"version": "95a936364f2685e9e040c6b179b553604d96de22",
"versionType": "git"
},
{
"status": "affected",
"version": "fba2cf348d9eb50b2049a73cc09313dab6d293f1",
"versionType": "git"
},
{
"status": "affected",
"version": "5.7.15",
"lessThan": "5.8",
"versionType": "semver"
},
{
"status": "affected",
"version": "5.8.2",
"lessThan": "5.9",
"versionType": "semver"
}
],
"programFiles": [
"drivers/net/ethernet/marvell/mvpp2/mvpp2_main.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "5.9"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "5.9",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.15.210",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.176",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.143",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.94",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.36",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.0.13",
"versionType": "semver",
"lessThanOrEqual": "7.0.*"
},
{
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/net/ethernet/marvell/mvpp2/mvpp2_main.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-06-25T09:16:39.160",
"references": [
{
"url": "https://git.kernel.org/stable/c/02e1b5c4d3b4c658b72c145427cded1bba613fc1",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/580f92f27cb8724bcc4be98ee89890eab524a2ae",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/5e8e2a9624df72fca7c736b2966b2cbf6c9c3ff6",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/8a2126c5afe89f8ceeb60a3afb9f075b736194cd",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/a03cdcedb2cbcc42551dc3e4746929e93c5352d5",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/a88b3293b556f4d8fba11db9a8061a6b0d3b69e6",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/d0c8c4fbd22d260fe28530260656c5fb3c20ce84",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-noinfo"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: mvpp2: refill RX buffers before XDP or skb use\n\nThe RX error path returns the current descriptor buffer to the hardware\nBM pool. That is only valid while the driver still owns the buffer.\n\nmvpp2_rx_refill() can fail after the current buffer has been handed to\nXDP or attached to an skb. In those cases mvpp2_run_xdp() may have\nrecycled, redirected, or queued the page for XDP_TX, and an skb free also\nretires the data buffer. Returning such a buffer to BM lets hardware DMA\ninto memory that is no longer owned by the RX ring.\n\nRefill the BM pool before handing the current buffer to XDP or to the\nskb. If the allocation fails there, drop the packet and return the\nstill-owned current buffer to BM, preserving the pool depth. Once the\nrefill succeeds, later local drops retire/free the current buffer instead\nof returning it to BM."
}
],
"lastModified": "2026-07-02T20:52:41.347",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AAAB1A2A-50F0-42C6-8E6D-C6E56FDFEA2A",
"versionEndExcluding": "5.8",
"versionStartIncluding": "5.7.15"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1BA712AB-1A90-4907-8864-5F3FFDA3963B",
"versionEndExcluding": "5.15.210",
"versionStartIncluding": "5.8.2"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C4446623-5F2B-4DD8-8666-9FAAC285A757",
"versionEndExcluding": "6.1.176",
"versionStartIncluding": "5.16"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9062F1CD-CAD6-4EA2-A73F-C06D4A887B8C",
"versionEndExcluding": "6.6.143",
"versionStartIncluding": "6.2"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "85421C0C-ABDE-4357-971C-67F9087DE1B9",
"versionEndExcluding": "6.12.94",
"versionStartIncluding": "6.7"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "389025D2-958D-41BD-BD96-70ED1033A9F3",
"versionEndExcluding": "6.18.36",
"versionStartIncluding": "6.13"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6A64BF9F-3BCA-42FD-98CB-8F03474D2B1E",
"versionEndExcluding": "7.0.13",
"versionStartIncluding": "6.19"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B1EF7059-E670-45F4-B422-54C40FA86390"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0D38F0BF-A728-4133-A358-D44A2F7EE6D6"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EC732D08-5F7B-46D9-B154-E60C7F4F0A97"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E5910A9D-F60A-409A-B486-FE66BFEBA9B9"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:7.1:rc5:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "81DFF19E-9CF8-49C6-8C36-1E4038622933"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:7.1:rc6:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B0E8FC71-3952-444C-83E9-718DBBBEC615"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:7.1:rc7:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1039E95A-8CC3-4C88-8FF9-5C08EEB861C9"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}