๐Ÿ” CVE Alert

CVE-2026-81002

CRITICAL 9.8

xdp: fix zero-copy frame layout

CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: xdp: fix zero-copy frame layout xdp_convert_zc_to_xdp_frame() clones an XSK packet into an order-0 page and advertises PAGE_SIZE as its frame size. It allows the copied frame to occupy the page tail needed by skb_shared_info and records zero headroom even when metadata separates the frame header from packet data. An AF_XDP zero-copy packet redirected through cpumap can therefore make the skb overlap skb_shared_info or place it beyond the allocated page. Limit the copied layout to SKB_WITH_OVERHEAD(PAGE_SIZE) and include the metadata length in frame headroom. Redirect callers already handle a NULL conversion result. BUG: KASAN: slab-out-of-bounds in skb_gro_receive Write of size 4 at addr ffff88800cf37004 by task cpumap/1/map:1/146 Call Trace: skb_gro_receive (net/core/gro.c:174) udp_gro_receive (net/ipv4/udp_offload.c:812) inet_gro_receive (net/ipv4/af_inet.c:1539) dev_gro_receive (net/core/gro.c:515) gro_receive_skb (net/core/gro.c:633) cpu_map_kthread_run (kernel/bpf/cpumap.c:395) kthread (kernel/kthread.c:436) ret_from_fork (arch/x86/kernel/process.c:164) ret_from_fork_asm (arch/x86/entry/entry_64.S:255) Kernel panic - not syncing: KASAN: panic_on_warn set ...

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 11, 2026
Last Updated Sep 14, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new critical vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Linux / Linux
b0d1beeff2a97a0cf1965ea8f1d13b8973f22582 < dcb6db9ca6515fcd3e00c93ec5e27dc7a0a7012f b0d1beeff2a97a0cf1965ea8f1d13b8973f22582 < 22092730129077c302d8c947bbe0876f0280c528 b0d1beeff2a97a0cf1965ea8f1d13b8973f22582 < ced3e18cd9b9caf630aaa1e1eac305f5192ba896 b0d1beeff2a97a0cf1965ea8f1d13b8973f22582 < 6de17275b3ccdf9887568b07e54da2e3597217cf b0d1beeff2a97a0cf1965ea8f1d13b8973f22582 < 444216dacdbebd3e52d5e704facafbb230da09e9 b0d1beeff2a97a0cf1965ea8f1d13b8973f22582 < 15d1f3c0dbe7a740f779337deb39f23cd8d002c8 b0d1beeff2a97a0cf1965ea8f1d13b8973f22582 < 68d7cc5512238693670fc19c7a615df631e10edf b0d1beeff2a97a0cf1965ea8f1d13b8973f22582 < 71283aaa6c65b3cec84caf1dc78560985737641f
Linux / Linux
4.20

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/dcb6db9ca6515fcd3e00c93ec5e27dc7a0a7012f git.kernel.org: https://git.kernel.org/stable/c/22092730129077c302d8c947bbe0876f0280c528 git.kernel.org: https://git.kernel.org/stable/c/ced3e18cd9b9caf630aaa1e1eac305f5192ba896 git.kernel.org: https://git.kernel.org/stable/c/6de17275b3ccdf9887568b07e54da2e3597217cf git.kernel.org: https://git.kernel.org/stable/c/444216dacdbebd3e52d5e704facafbb230da09e9 git.kernel.org: https://git.kernel.org/stable/c/15d1f3c0dbe7a740f779337deb39f23cd8d002c8 git.kernel.org: https://git.kernel.org/stable/c/68d7cc5512238693670fc19c7a615df631e10edf git.kernel.org: https://git.kernel.org/stable/c/71283aaa6c65b3cec84caf1dc78560985737641f