PT-2026-93690 · Linux+1 · Linux Kernel+1
CVE-2026-90049
·
Published
2026-09-16
·
Updated
2026-09-24
CVSS v3.1
9.3
Critical
| Vector | AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An issue exists in the
skb zerocopy() function where it incorrectly calls skb tx error() on the source skb during an skb orphan frags() failure. This operation is destructive to the source skb, which the copy helper does not own. This process completes the zerocopy uarg and clears the SKBFL ALL ZEROCOPY flag, including the SKBFL SHARED FRAG page-ownership marker. In the Open vSwitch OVS ACTION ATTR USERSPACE path, the skb is not freed upon this error, allowing it to continue through remaining actions. Because the SKBFL SHARED FRAG flag is cleared while the skb is still in flight, a subsequent local ESP delivery may cause esp input() to bypass skb cow data() and decrypt data over fragments that the skb no longer privately owns.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel
Openvswitch