PT-2026-94490 · Linux · Linux Kernel

CVE-2026-90142

·

Published

2026-09-17

·

Updated

2026-09-24

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the virtio net driver where the virtnet rx resize() function fails to resize the rq->xsk buffs XSK buffer array when an AF XDP socket is attached. If the ring size increases, the virtnet rx resume() function may perform a write operation past the end of the array, leading to memory corruption.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-90142
OPENSUSE-SU-2026:11880-1

Affected Products

Linux Kernel