In the Linux kernel, the following vulnerability has been resolved: net: gro: don't merge zcopy skbs skb_gro_receive() can currently copy frags between the source and GRO skb, without checking the …
High CVSS 7.8
Summary
In the Linux kernel, the following vulnerability has been resolved: net: gro: don't merge zcopy skbs skb_gro_receive() can currently copy frags between the source and GRO skb, without checking the zerocopy status, and in particular the SKBFL_MANAGED_FRAG_REFS flag. When SKBFL_MANAGED_FRAG_REFS is set, the skb doesn't hold a reference on the pages in shinfo->frags. Appending those frags to another skb's frags without fixing up the page refcount can lead to UAF. When either the last skb in th…
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
Sources
- NVD DATABASE
Original Links
- https://git.kernel.org/stable/c/1f9c828556416fbe3f49386708ce999fc4d4da06 Patch
- https://git.kernel.org/stable/c/3c6cc9f2ca65b6dd61b1af75452dc0e1cd0aad8d Patch
- https://git.kernel.org/stable/c/44bea2032af0425e4ce6d26a8af0ede79db49ec1 Patch
- https://git.kernel.org/stable/c/479084ae0e1d9cb7929cb4298d35623de189f80a Patch
- https://git.kernel.org/stable/c/4db79a322db8c97f7b73b8a347395ef4d685eb40 Patch
- https://git.kernel.org/stable/c/e334cbf3388fd9334503a778a82d9e9f14dd2f71 Patch
- https://access.redhat.com/errata/RHSA-2026:27708 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:27731 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:27735 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:36018 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:44259
- https://access.redhat.com/errata/RHSA-2026:44262
- https://access.redhat.com/errata/RHSA-2026:44270
- https://access.redhat.com/security/cve/CVE-2026-46323 Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2479832 Third Party Advisory
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-46323.json Third Party Advisory
Timeline
- nvd_ingest NVD