In the Linux kernel, the following vulnerability has been resolved: net: gro: don't merge zcopy skbs skb_gro_receive() can currently copy frags between the source and GRO skb, without checking the …
高危 CVSS 7.8
摘要
In the Linux kernel, the following vulnerability has been resolved: net: gro: don't merge zcopy skbs skb_gro_receive() can currently copy frags between the source and GRO skb, without checking the zerocopy status, and in particular the SKBFL_MANAGED_FRAG_REFS flag. When SKBFL_MANAGED_FRAG_REFS is set, the skb doesn't hold a reference on the pages in shinfo->frags. Appending those frags to another skb's frags without fixing up the page refcount can lead to UAF. When either the last skb in th…
中文摘要建设中,暂以英文摘要呈现(DR-003 v2)。
深度研判 · 自动通道
该漏洞尚未生成深度研判报告(DR-003 v2 AI pipeline 建设中)。
受影响产品
- :
数据来源
- NVD DATABASE
原始链接
- https://git.kernel.org/stable/c/1f9c828556416fbe3f49386708ce999fc4d4da06 Patch
- https://git.kernel.org/stable/c/3c6cc9f2ca65b6dd61b1af75452dc0e1cd0aad8d Patch
- https://git.kernel.org/stable/c/44bea2032af0425e4ce6d26a8af0ede79db49ec1 Patch
- https://git.kernel.org/stable/c/479084ae0e1d9cb7929cb4298d35623de189f80a Patch
- https://git.kernel.org/stable/c/4db79a322db8c97f7b73b8a347395ef4d685eb40 Patch
- https://git.kernel.org/stable/c/e334cbf3388fd9334503a778a82d9e9f14dd2f71 Patch
- https://access.redhat.com/errata/RHSA-2026:27708 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:27731 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:27735 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:36018 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:44259
- https://access.redhat.com/errata/RHSA-2026:44262
- https://access.redhat.com/errata/RHSA-2026:44270
- https://access.redhat.com/security/cve/CVE-2026-46323 Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2479832 Third Party Advisory
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-46323.json Third Party Advisory
时间线
- nvd_ingest NVD