PT-2026-93690 · Linux+1 · Linux Kernel+1

CVE-2026-90049

·

Published

2026-09-16

·

Updated

2026-09-24

CVSS v3.1

9.3

Critical

VectorAV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the skb zerocopy() function where it incorrectly calls skb tx error() on the source skb during an skb orphan frags() failure. This operation is destructive to the source skb, which the copy helper does not own. This process completes the zerocopy uarg and clears the SKBFL ALL ZEROCOPY flag, including the SKBFL SHARED FRAG page-ownership marker. In the Open vSwitch OVS ACTION ATTR USERSPACE path, the skb is not freed upon this error, allowing it to continue through remaining actions. Because the SKBFL SHARED FRAG flag is cleared while the skb is still in flight, a subsequent local ESP delivery may cause esp input() to bypass skb cow data() and decrypt data over fragments that the skb no longer privately owns.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-101409
CVE-2026-90049
OPENSUSE-SU-2026:11880-1

Affected Products

Linux Kernel
Openvswitch