๐Ÿ” CVE Alert

CVE-2026-46322

UNKNOWN 0.0

tun: free page on build_skb failure in tun_xdp_one()

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: tun: free page on build_skb failure in tun_xdp_one() When build_skb() fails in tun_xdp_one(), the function sets ret to -ENOMEM and jumps to the out label, which returns without freeing the page that vhost_net_build_xdp() allocated for the frame. As with the short-frame rejection path, tun_sendmsg() discards the per-buffer error and still returns total_len, so vhost_tx_batch() takes the success path and never frees the page. Each build_skb() failure in a batch leaks one page-frag chunk. Free the page before taking the error path, matching the put_page() the other error exits of tun_xdp_one() already perform.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Jun 9, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
043d222f93ab8c76b56a3b315cd8692e35affb6c < d16e38fac09a47bfcf98c1ad65a1bb53f94540f5 043d222f93ab8c76b56a3b315cd8692e35affb6c < aa308e9dbb9acb17cacdbbce9e4504f69bac8385 043d222f93ab8c76b56a3b315cd8692e35affb6c < 4fefc6156a162a9f50035c12091a5e5130c82c6e 043d222f93ab8c76b56a3b315cd8692e35affb6c < aa8963fdce667a42fb7f0bdd2909fadcab02f9a8
Linux / Linux
4.20

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/d16e38fac09a47bfcf98c1ad65a1bb53f94540f5 git.kernel.org: https://git.kernel.org/stable/c/aa308e9dbb9acb17cacdbbce9e4504f69bac8385 git.kernel.org: https://git.kernel.org/stable/c/4fefc6156a162a9f50035c12091a5e5130c82c6e git.kernel.org: https://git.kernel.org/stable/c/aa8963fdce667a42fb7f0bdd2909fadcab02f9a8