PT-2026-94490 · Linux · Linux Kernel
CVE-2026-90142
·
Published
2026-09-17
·
Updated
2026-09-24
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An issue exists in the
virtio net driver where the virtnet rx resize() function fails to resize the rq->xsk buffs XSK buffer array when an AF XDP socket is attached. If the ring size increases, the virtnet rx resume() function may perform a write operation past the end of the array, leading to memory corruption.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel