๐Ÿ” CVE Alert

CVE-2026-90051

UNKNOWN 0.0

tcp: reject non zerocopy devmem tx

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: tcp: reject non zerocopy devmem tx Devmem tcp tx doesn't work without zero-copy, however it's not currently enforced if NETIF_F_SG isn't present. In this case, tcp_sendmsg_locked() will try the copy path and try to copy data from an iovec which consists of offsets into the dma-buf and would normally fail. Moreover, d9c56501c72fd ("net: tcp: block mixing readable and unreadable frags") relies on that and assumes that the devmem binding is present IFF we're using the zero-copy path, which can be used to mix net-iov and pages in a single skb, and break invariants. Let's reject devmem tx without zero-copy. Note, the parameter check the patch is modifying is too loose, we can create an io_uring request with dmabuf_id and all ZC flags, but which won't have the binding. We replace it with stricter validation.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 17, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
bd61848900bff597764238f3a8ec67c815cd316e < 2151b2bcf6fcec52665f606eed20da068447f0b7 bd61848900bff597764238f3a8ec67c815cd316e < b04326c7927af7048fd4e730f5770cca350d0a60 bd61848900bff597764238f3a8ec67c815cd316e < 125755776bc6d4dd53eaf551c87e3d460625d638
Linux / Linux
6.16

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/2151b2bcf6fcec52665f606eed20da068447f0b7 git.kernel.org: https://git.kernel.org/stable/c/b04326c7927af7048fd4e730f5770cca350d0a60 git.kernel.org: https://git.kernel.org/stable/c/125755776bc6d4dd53eaf551c87e3d460625d638