๐Ÿ” CVE Alert

CVE-2026-46331

HIGH 7.8

net/sched: fix pedit partial COW leading to page cache corruption

CVSS Score
7.8
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: net/sched: fix pedit partial COW leading to page cache corruption tcf_pedit_act() computes the COW range for skb_ensure_writable() once before the key loop using tcfp_off_max_hint, but the hint does not account for the runtime header offset added by typed keys. This can leave part of the write region un-COW'd. Fix by moving skb_ensure_writable() inside the per-key loop where the actual write offset is known, and add overflow checking on the offset arithmetic. For negative offsets (e.g. Ethernet header edits at ingress), use skb_cow() to COW the headroom instead. Guard offset_valid() against INT_MIN, where negation is undefined.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Jun 16, 2026
Last Updated Jul 15, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new high vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Linux / Linux
abe35bf3be51482593076d516a680d79e5fbc8e1 < 544d857b42a1734b923040e13aa61a6fd4746cf2 b773640d5bb9e2acfd91e2695717af04d47aa116 < d5d01d35a5a7d36f7cb679b67d9cbdd5205672dc 8b796475fd7882663a870456466a4fb315cc1bd6 < a071e057518decc5e3bec89855758f5f8786f2c5 8b796475fd7882663a870456466a4fb315cc1bd6 < b685d6ef6f07a3b5ce814565a25f39f2157538a5 8b796475fd7882663a870456466a4fb315cc1bd6 < 2bec122b9fb91507a758ab5e3e5c4fbe7cb3f61b 8b796475fd7882663a870456466a4fb315cc1bd6 < b198ed4e52580a7238c7c7082f03906f8b310313 8b796475fd7882663a870456466a4fb315cc1bd6 < 3dee9d0c198faeb95d052c1b94c2958751a28512 8b796475fd7882663a870456466a4fb315cc1bd6 < 899ee91156e57784090c5565e4f31bd7dbffbc5a d0c38a914b0c4c21d553da801003d36979016726 2ec2dd7d51a9320151f275ddbb2b53260fb32ca1 c19cc520b3d69904e9518d401ad0df7f4702aca0 5.10.117 < 5.10.260 5.15.41 < 5.15.211 4.19.244 < 4.20 5.4.195 < 5.5 5.17.9 < 5.18
Linux / Linux
5.18

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/544d857b42a1734b923040e13aa61a6fd4746cf2 git.kernel.org: https://git.kernel.org/stable/c/d5d01d35a5a7d36f7cb679b67d9cbdd5205672dc git.kernel.org: https://git.kernel.org/stable/c/a071e057518decc5e3bec89855758f5f8786f2c5 git.kernel.org: https://git.kernel.org/stable/c/b685d6ef6f07a3b5ce814565a25f39f2157538a5 git.kernel.org: https://git.kernel.org/stable/c/2bec122b9fb91507a758ab5e3e5c4fbe7cb3f61b git.kernel.org: https://git.kernel.org/stable/c/b198ed4e52580a7238c7c7082f03906f8b310313 git.kernel.org: https://git.kernel.org/stable/c/3dee9d0c198faeb95d052c1b94c2958751a28512 git.kernel.org: https://git.kernel.org/stable/c/899ee91156e57784090c5565e4f31bd7dbffbc5a github.com: https://github.com/sgkdev/packet_edit_meme/tree/main access.redhat.com: https://access.redhat.com/security/cve/CVE-2026-46331 bugzilla.redhat.com: https://bugzilla.redhat.com/show_bug.cgi?id=2479492 security.access.redhat.com: https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-46331.json access.redhat.com: https://access.redhat.com/errata/RHSA-2026:27709 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:33666 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:34048 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:28887 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:28962 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:29080 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:34098 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:29856 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:29863 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:29799 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:29833 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:29794 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:27731 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:27288 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:27705 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:27713 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:27708 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:27789 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:33225 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:27353 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:33220 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:27707 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:27704 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:27355 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:33219 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:33221 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:33222 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:33223 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:33224 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:27354 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:27706