« Volver al listado

CVE-2026-90049

Estado: RecibidaCrítica (9.3)—

In the Linux kernel, the following vulnerability has been resolved:

net: skbuff: don't skb_tx_error() the source skb in skb_zerocopy()

skb_zerocopy() copies frags from @from into @to. On an skb_orphan_frags() failure it calls skb_tx_error(@from), a destructive operation on the source skb the copy helper does not own. That completes @from's zerocopy uarg and clears SKBFL_ALL_ZEROCOPY, including the SKBFL_SHARED_FRAG page-ownership marker.

Both callers already report the failure on their own drop path. nfnetlink_queue does it at nla_put_failure, and Open vSwitch does it in the flow-miss drop arm of ovs_dp_process_packet(), so nothing is lost by dropping it here.

Leer descripción completaMostrar menos

On Open vSwitch's OVS_ACTION_ATTR_USERSPACE path the skb is not freed on this error: do_execute_actions() ignores output_userspace()'s return value and, unless the upcall was the last action, keeps forwarding the same skb through the flow's remaining actions. The uarg is completed while that skb is still in flight, telling the producer its buffers are free, and SKBFL_SHARED_FRAG is cleared on an skb the rest of the stack still handles. That flag is what makes esp_input() call skb_cow_data() instead of decrypting in place, so a later local ESP delivery can decrypt over frags the skb does not own privately.

Leave error reporting to the callers.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vulnerabilidad local en kernel Linux sin privilegios (AV:L/PR:N) que corrompe estado de memoria en zerocopy, permitiendo lectura/escritura de buffer no propietario vía ESP criptografía; impacto crítico (CVSS 9.8) en integridad y disponibilidad.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-90049",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 9.3,
          "attackVector": "LOCAL",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 6,
        "exploitabilityScore": 2.5
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "36d5fe6a000790f56039afe26834265db0a3ad4c",
              "lessThan": "849bdb83123760a865bcb2970127f4c0b9423ba3",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "36d5fe6a000790f56039afe26834265db0a3ad4c",
              "lessThan": "fb10e0e9b220a2eed08931a60dbaad9a2370c908",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "36d5fe6a000790f56039afe26834265db0a3ad4c",
              "lessThan": "767ec2a65cc022d303b0c9c12811e7db22057341",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "36d5fe6a000790f56039afe26834265db0a3ad4c",
              "lessThan": "8069643ae64dfdf634b6c78c7f622e5323031436",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "36d5fe6a000790f56039afe26834265db0a3ad4c",
              "lessThan": "04dd250a78e268af3e7124beb1dc10ec1dd88d60",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "36d5fe6a000790f56039afe26834265db0a3ad4c",
              "lessThan": "a13b1e80e5015cd732440b475c0ef443dc4a2157",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "36d5fe6a000790f56039afe26834265db0a3ad4c",
              "lessThan": "bab5a851e44a3601d31f2aa8043f385bb50ac5d9",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "36d5fe6a000790f56039afe26834265db0a3ad4c",
              "lessThan": "8ece906150128d5ec2462aabcc978c568433eca4",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "c5f0c0e7525443add533495e93ba8de6feab2396",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1674b4bf3eea3cac51b70778e89f8025f7cfe695",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "3.10.51",
              "lessThan": "3.11",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "3.12.40",
              "lessThan": "3.13",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "net/core/skbuff.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "3.14"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "3.14",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.270",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.221",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.188",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.157",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.110",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.51",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.5",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "net/core/skbuff.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-16T11:17:18.263",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/04dd250a78e268af3e7124beb1dc10ec1dd88d60",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/767ec2a65cc022d303b0c9c12811e7db22057341",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/8069643ae64dfdf634b6c78c7f622e5323031436",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/849bdb83123760a865bcb2970127f4c0b9423ba3",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/8ece906150128d5ec2462aabcc978c568433eca4",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/a13b1e80e5015cd732440b475c0ef443dc4a2157",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/bab5a851e44a3601d31f2aa8043f385bb50ac5d9",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/fb10e0e9b220a2eed08931a60dbaad9a2370c908",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: skbuff: don't skb_tx_error() the source skb in skb_zerocopy()\n\nskb_zerocopy() copies frags from @from into @to. On an\nskb_orphan_frags() failure it calls skb_tx_error(@from), a destructive\noperation on the source skb the copy helper does not own. That completes\n@from's zerocopy uarg and clears SKBFL_ALL_ZEROCOPY, including the\nSKBFL_SHARED_FRAG page-ownership marker.\n\nBoth callers already report the failure on their own drop path.\nnfnetlink_queue does it at nla_put_failure, and Open vSwitch does it in\nthe flow-miss drop arm of ovs_dp_process_packet(), so nothing is lost by\ndropping it here.\n\nOn Open vSwitch's OVS_ACTION_ATTR_USERSPACE path the skb is not freed on\nthis error: do_execute_actions() ignores output_userspace()'s return\nvalue and, unless the upcall was the last action, keeps forwarding the\nsame skb through the flow's remaining actions. The uarg is completed\nwhile that skb is still in flight, telling the producer its buffers are\nfree, and SKBFL_SHARED_FRAG is cleared on an skb the rest of the stack\nstill handles. That flag is what makes esp_input() call skb_cow_data()\ninstead of decrypting in place, so a later local ESP delivery can\ndecrypt over frags the skb does not own privately.\n\nLeave error reporting to the callers."
    },
    {
      "lang": "es",
      "value": "En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta:\n\nnet: skbuff: no llamar a skb_tx_error() al skb de origen en skb_zerocopy()\n\nskb_zerocopy() copia fragmentos de @from a @to. En caso de fallo de skb_orphan_frags(), llama a skb_tx_error(@from), una operación destructiva en el skb de origen que el ayudante de copia no posee. Eso completa el uarg de zerocopy de @from y borra SKBFL_ALL_ZEROCOPY, incluyendo el marcador de propiedad de página SKBFL_SHARED_FRAG.\n\nAmbos llamadores ya informan del fallo en su propia ruta de descarte. nfnetlink_queue lo hace en nla_put_failure, y Open vSwitch lo hace en el brazo de descarte por fallo de flujo de ovs_dp_process_packet(), por lo que no se pierde nada al descartarlo aquí.\n\nEn la ruta OVS_ACTION_ATTR_USERSPACE de Open vSwitch, el skb no se libera en este error: do_execute_actions() ignora el valor de retorno de output_userspace() y, a menos que la llamada ascendente fuera la última acción, sigue reenviando el mismo skb a través de las acciones restantes del flujo. El uarg se completa mientras ese skb todavía está en tránsito, indicando al productor que sus búferes están libres, y SKBFL_SHARED_FRAG se borra en un skb que el resto de la pila aún maneja. Esa bandera es lo que hace que esp_input() llame a skb_cow_data() en lugar de descifrar in situ, para que una entrega ESP local posterior pueda descifrar sobre fragmentos que el skb no posee de forma privada.\n\nDejar el informe de errores a los llamadores."
    }
  ],
  "lastModified": "2026-09-28T23:10:00.143",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}