← All Advisories

CVE-2026-90049

Last refreshed2026-10-10

Status: UPDATED  |  Advisory ID: CVE-2026-90049

Key Details

CVECVE-2026-90049
CVSS Score / Version9.3 (Critical) / CVSS v3.1
Updated2026-09-28
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVSS Proseattack vector is local; attack complexity is low; privileges required is none; user interaction is none; scope is changed; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsLinux Kernel

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux Kernel
SubsystemsOT Supporting Infrastructure
SectorsAll Sectors

What to Know

In the Linux kernel, the following vulnerability has been resolved:

net: skbuff: don't skb_tx_error() the source skb in skb_zerocopy()

skb_zerocopy() copies frags from @from into @to. On an

skb_orphan_frags() failure it calls skb_tx_error(@from), a destructive

operation on the source skb the copy helper does not own. That completes

@from's zerocopy uarg and clears SKBFL_ALL_ZEROCOPY, including the

SKBFL_SHARED_FRAG page-ownership marker.

Both callers already report the failure on their own drop path.

nfnetlink_queue does it at nla_put_failure, and Open vSwitch does it in

the flow-miss drop arm of ovs_dp_process_packet(), so nothing is lost by

dropping it here.

On Open vSwitch's OVS_ACTION_ATTR_USERSPACE path the skb is not freed on

this error: do_execute_actions() ignores output_userspace()'s return

value and, unless the upcall was the last action, keeps forwarding the

same skb through the flow's remaining actions. The uarg is completed

while that skb is still in flight, telling the producer its buffers are

free, and SKBFL_SHARED_FRAG is cleared on an skb the rest of the stack

still handles. That flag is what makes esp_input() call skb_cow_data()

instead of decrypting in place, so a later local ESP delivery can

decrypt over frags the skb does not own privately.

Leave error reporting to the callers. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-90049
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-90049