CVE-2026-81002
In the Linux kernel, the following vulnerability has been resolved:
xdp: fix zero-copy frame layout
xdp_convert_zc_to_xdp_frame() clones an XSK packet into an order-0 page and advertises PAGE_SIZE as its frame size. It allows the copied frame to occupy the page tail needed by skb_shared_info and records zero headroom even when metadata separates the frame header from packet data. An AF_XDP zero-copy packet redirected through cpumap can therefore make the skb overlap skb_shared_info or place it beyond the allocated page.
Limit the copied layout to SKB_WITH_OVERHEAD(PAGE_SIZE) and include the metadata length in frame headroom. Redirect callers already handle a NULL conversion result.
Leer descripción completaMostrar menos
BUG: KASAN: slab-out-of-bounds in skb_gro_receive Write of size 4 at addr ffff88800cf37004 by task cpumap/1/map:1/146 Call Trace: skb_gro_receive (net/core/gro.c:174) udp_gro_receive (net/ipv4/udp_offload.c:812) inet_gro_receive (net/ipv4/af_inet.c:1539) dev_gro_receive (net/core/gro.c:515) gro_receive_skb (net/core/gro.c:633) cpu_map_kthread_run (kernel/bpf/cpumap.c:395) kthread (kernel/kthread.c:436) ret_from_fork (arch/x86/kernel/process.c:164) ret_from_fork_asm (arch/x86/entry/entry_64.S:255) Kernel panic - not syncing: KASAN: panic_on_warn set ...
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 9.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.51%
- Percentil entre todas las CVEs puntuadas: 42
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1190Exploit Public-Facing Applicationinitial access75 % - Impacto principal
T1499.004Application or System Exploitationimpact70 % - Impacto secundario
T1068Exploitation for Privilege Escalationprivilege escalation65 %
Vulnerabilidad de red remota (AV:N, PR:N, UI:N) en kernel Linux explotable sin privilegios. Impactos: DoS por corrupción de memoria (slab-out-of-bounds, kernel panic) y potencial escalada local (KASAN puede ser aprovechado).
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/15d1f3c0dbe7a740f779337deb39f23cd8d002c8
- https://git.kernel.org/stable/c/22092730129077c302d8c947bbe0876f0280c528
- https://git.kernel.org/stable/c/444216dacdbebd3e52d5e704facafbb230da09e9
- https://git.kernel.org/stable/c/68d7cc5512238693670fc19c7a615df631e10edf
- https://git.kernel.org/stable/c/6de17275b3ccdf9887568b07e54da2e3597217cf
- https://git.kernel.org/stable/c/71283aaa6c65b3cec84caf1dc78560985737641f
- https://git.kernel.org/stable/c/ced3e18cd9b9caf630aaa1e1eac305f5192ba896
- https://git.kernel.org/stable/c/dcb6db9ca6515fcd3e00c93ec5e27dc7a0a7012f
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-81002",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Secondary",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "b0d1beeff2a97a0cf1965ea8f1d13b8973f22582",
"lessThan": "dcb6db9ca6515fcd3e00c93ec5e27dc7a0a7012f",
"versionType": "git"
},
{
"status": "affected",
"version": "b0d1beeff2a97a0cf1965ea8f1d13b8973f22582",
"lessThan": "22092730129077c302d8c947bbe0876f0280c528",
"versionType": "git"
},
{
"status": "affected",
"version": "b0d1beeff2a97a0cf1965ea8f1d13b8973f22582",
"lessThan": "ced3e18cd9b9caf630aaa1e1eac305f5192ba896",
"versionType": "git"
},
{
"status": "affected",
"version": "b0d1beeff2a97a0cf1965ea8f1d13b8973f22582",
"lessThan": "6de17275b3ccdf9887568b07e54da2e3597217cf",
"versionType": "git"
},
{
"status": "affected",
"version": "b0d1beeff2a97a0cf1965ea8f1d13b8973f22582",
"lessThan": "444216dacdbebd3e52d5e704facafbb230da09e9",
"versionType": "git"
},
{
"status": "affected",
"version": "b0d1beeff2a97a0cf1965ea8f1d13b8973f22582",
"lessThan": "15d1f3c0dbe7a740f779337deb39f23cd8d002c8",
"versionType": "git"
},
{
"status": "affected",
"version": "b0d1beeff2a97a0cf1965ea8f1d13b8973f22582",
"lessThan": "68d7cc5512238693670fc19c7a615df631e10edf",
"versionType": "git"
},
{
"status": "affected",
"version": "b0d1beeff2a97a0cf1965ea8f1d13b8973f22582",
"lessThan": "71283aaa6c65b3cec84caf1dc78560985737641f",
"versionType": "git"
}
],
"programFiles": [
"net/core/xdp.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "4.20"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "4.20",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.10.270",
"versionType": "semver",
"lessThanOrEqual": "5.10.*"
},
{
"status": "unaffected",
"version": "5.15.221",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.188",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.157",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.109",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.50",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2.4",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"net/core/xdp.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-11T20:19:08.483",
"references": [
{
"url": "https://git.kernel.org/stable/c/15d1f3c0dbe7a740f779337deb39f23cd8d002c8",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/22092730129077c302d8c947bbe0876f0280c528",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/444216dacdbebd3e52d5e704facafbb230da09e9",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/68d7cc5512238693670fc19c7a615df631e10edf",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/6de17275b3ccdf9887568b07e54da2e3597217cf",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/71283aaa6c65b3cec84caf1dc78560985737641f",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/ced3e18cd9b9caf630aaa1e1eac305f5192ba896",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/dcb6db9ca6515fcd3e00c93ec5e27dc7a0a7012f",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nxdp: fix zero-copy frame layout\n\nxdp_convert_zc_to_xdp_frame() clones an XSK packet into an order-0 page\nand advertises PAGE_SIZE as its frame size. It allows the copied frame\nto occupy the page tail needed by skb_shared_info and records zero\nheadroom even when metadata separates the frame header from packet data.\nAn AF_XDP zero-copy packet redirected through cpumap can therefore make\nthe skb overlap skb_shared_info or place it beyond the allocated page.\n\nLimit the copied layout to SKB_WITH_OVERHEAD(PAGE_SIZE) and include the\nmetadata length in frame headroom. Redirect callers already handle a\nNULL conversion result.\n\nBUG: KASAN: slab-out-of-bounds in skb_gro_receive\nWrite of size 4 at addr ffff88800cf37004 by task cpumap/1/map:1/146\nCall Trace:\n skb_gro_receive (net/core/gro.c:174)\n udp_gro_receive (net/ipv4/udp_offload.c:812)\n inet_gro_receive (net/ipv4/af_inet.c:1539)\n dev_gro_receive (net/core/gro.c:515)\n gro_receive_skb (net/core/gro.c:633)\n cpu_map_kthread_run (kernel/bpf/cpumap.c:395)\n kthread (kernel/kthread.c:436)\n ret_from_fork (arch/x86/kernel/process.c:164)\n ret_from_fork_asm (arch/x86/entry/entry_64.S:255)\nKernel panic - not syncing: KASAN: panic_on_warn set ..."
}
],
"lastModified": "2026-09-14T13:18:54.553",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}