PT-2026-94399 · Linux · Linux Kernel

CVE-2026-90051

·

Published

2026-09-17

·

Updated

2026-09-24

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the TCP implementation where devmem TX is not properly enforced to require zero-copy when NETIF F SG is absent. In such scenarios, the tcp sendmsg locked() function attempts a copy path using an iovec containing offsets into the dma-buf, which typically fails. This behavior can lead to the mixing of net-iov and pages within a single skb, breaking internal invariants. Additionally, loose parameter validation allows the creation of io uring requests with dmabuf id and zero-copy flags without the necessary binding.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-90051
OPENSUSE-SU-2026:11880-1

Affected Products

Linux Kernel