PT-2026-94399 · Linux · Linux Kernel
CVE-2026-90051
·
Published
2026-09-17
·
Updated
2026-09-24
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An issue exists in the TCP implementation where devmem TX is not properly enforced to require zero-copy when
NETIF F SG is absent. In such scenarios, the tcp sendmsg locked() function attempts a copy path using an iovec containing offsets into the dma-buf, which typically fails. This behavior can lead to the mixing of net-iov and pages within a single skb, breaking internal invariants. Additionally, loose parameter validation allows the creation of io uring requests with dmabuf id and zero-copy flags without the necessary binding.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel