CVE-2026-90049 (GCVE-0-2026-90049)

Vulnerability from cvelistv5 – Published: 2026-09-16 10:33 – Updated: 2026-09-16 14:42
VLAI
Title
net: skbuff: don't skb_tx_error() the source skb in skb_zerocopy()
Summary
In the Linux kernel, the following vulnerability has been resolved: net: skbuff: don't skb_tx_error() the source skb in skb_zerocopy() skb_zerocopy() copies frags from @from into @to. On an skb_orphan_frags() failure it calls skb_tx_error(@from), a destructive operation on the source skb the copy helper does not own. That completes @from's zerocopy uarg and clears SKBFL_ALL_ZEROCOPY, including the SKBFL_SHARED_FRAG page-ownership marker. Both callers already report the failure on their own drop path. nfnetlink_queue does it at nla_put_failure, and Open vSwitch does it in the flow-miss drop arm of ovs_dp_process_packet(), so nothing is lost by dropping it here. On Open vSwitch's OVS_ACTION_ATTR_USERSPACE path the skb is not freed on this error: do_execute_actions() ignores output_userspace()'s return value and, unless the upcall was the last action, keeps forwarding the same skb through the flow's remaining actions. The uarg is completed while that skb is still in flight, telling the producer its buffers are free, and SKBFL_SHARED_FRAG is cleared on an skb the rest of the stack still handles. That flag is what makes esp_input() call skb_cow_data() instead of decrypting in place, so a later local ESP delivery can decrypt over frags the skb does not own privately. Leave error reporting to the callers.
Impacted products
Vendor Product Version
Linux Linux Affected: 36d5fe6a000790f56039afe26834265db0a3ad4c , < 849bdb83123760a865bcb2970127f4c0b9423ba3 (git)
Affected: 36d5fe6a000790f56039afe26834265db0a3ad4c , < fb10e0e9b220a2eed08931a60dbaad9a2370c908 (git)
Affected: 36d5fe6a000790f56039afe26834265db0a3ad4c , < 767ec2a65cc022d303b0c9c12811e7db22057341 (git)
Affected: 36d5fe6a000790f56039afe26834265db0a3ad4c , < 8069643ae64dfdf634b6c78c7f622e5323031436 (git)
Affected: 36d5fe6a000790f56039afe26834265db0a3ad4c , < 04dd250a78e268af3e7124beb1dc10ec1dd88d60 (git)
Affected: 36d5fe6a000790f56039afe26834265db0a3ad4c , < a13b1e80e5015cd732440b475c0ef443dc4a2157 (git)
Affected: 36d5fe6a000790f56039afe26834265db0a3ad4c , < bab5a851e44a3601d31f2aa8043f385bb50ac5d9 (git)
Affected: 36d5fe6a000790f56039afe26834265db0a3ad4c , < 8ece906150128d5ec2462aabcc978c568433eca4 (git)
Affected: c5f0c0e7525443add533495e93ba8de6feab2396 (git)
Affected: 1674b4bf3eea3cac51b70778e89f8025f7cfe695 (git)
Affected: 3.10.51 , < 3.11 (semver)
Affected: 3.12.40 , < 3.13 (semver)
Create a notification for this product.
Linux Linux Affected: 3.14
Unaffected: 0 , < 3.14 (semver)
Unaffected: 5.10.270 , ≤ 5.10.* (semver)
Unaffected: 5.15.221 , ≤ 5.15.* (semver)
Unaffected: 6.1.188 , ≤ 6.1.* (semver)
Unaffected: 6.6.157 , ≤ 6.6.* (semver)
Unaffected: 6.12.110 , ≤ 6.12.* (semver)
Unaffected: 6.18.51 , ≤ 6.18.* (semver)
Unaffected: 7.2.5 , ≤ 7.2.* (semver)
Unaffected: 7.3-rc1 , ≤ * (original_commit_for_fix)
Create a notification for this product.
Show details on NVD website

{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "net/core/skbuff.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "849bdb83123760a865bcb2970127f4c0b9423ba3",
              "status": "affected",
              "version": "36d5fe6a000790f56039afe26834265db0a3ad4c",
              "versionType": "git"
            },
            {
              "lessThan": "fb10e0e9b220a2eed08931a60dbaad9a2370c908",
              "status": "affected",
              "version": "36d5fe6a000790f56039afe26834265db0a3ad4c",
              "versionType": "git"
            },
            {
              "lessThan": "767ec2a65cc022d303b0c9c12811e7db22057341",
              "status": "affected",
              "version": "36d5fe6a000790f56039afe26834265db0a3ad4c",
              "versionType": "git"
            },
            {
              "lessThan": "8069643ae64dfdf634b6c78c7f622e5323031436",
              "status": "affected",
              "version": "36d5fe6a000790f56039afe26834265db0a3ad4c",
              "versionType": "git"
            },
            {
              "lessThan": "04dd250a78e268af3e7124beb1dc10ec1dd88d60",
              "status": "affected",
              "version": "36d5fe6a000790f56039afe26834265db0a3ad4c",
              "versionType": "git"
            },
            {
              "lessThan": "a13b1e80e5015cd732440b475c0ef443dc4a2157",
              "status": "affected",
              "version": "36d5fe6a000790f56039afe26834265db0a3ad4c",
              "versionType": "git"
            },
            {
              "lessThan": "bab5a851e44a3601d31f2aa8043f385bb50ac5d9",
              "status": "affected",
              "version": "36d5fe6a000790f56039afe26834265db0a3ad4c",
              "versionType": "git"
            },
            {
              "lessThan": "8ece906150128d5ec2462aabcc978c568433eca4",
              "status": "affected",
              "version": "36d5fe6a000790f56039afe26834265db0a3ad4c",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "c5f0c0e7525443add533495e93ba8de6feab2396",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1674b4bf3eea3cac51b70778e89f8025f7cfe695",
              "versionType": "git"
            },
            {
              "lessThan": "3.11",
              "status": "affected",
              "version": "3.10.51",
              "versionType": "semver"
            },
            {
              "lessThan": "3.13",
              "status": "affected",
              "version": "3.12.40",
              "versionType": "semver"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "net/core/skbuff.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "3.14"
            },
            {
              "lessThan": "3.14",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.10.*",
              "status": "unaffected",
              "version": "5.10.270",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.15.*",
              "status": "unaffected",
              "version": "5.15.221",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.1.*",
              "status": "unaffected",
              "version": "6.1.188",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.157",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.12.*",
              "status": "unaffected",
              "version": "6.12.110",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.18.*",
              "status": "unaffected",
              "version": "6.18.51",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "7.2.*",
              "status": "unaffected",
              "version": "7.2.5",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.10.270",
                  "versionStartIncluding": "3.14",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.15.221",
                  "versionStartIncluding": "3.14",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1.188",
                  "versionStartIncluding": "3.14",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.157",
                  "versionStartIncluding": "3.14",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12.110",
                  "versionStartIncluding": "3.14",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.18.51",
                  "versionStartIncluding": "3.14",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.2.5",
                  "versionStartIncluding": "3.14",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.3-rc1",
                  "versionStartIncluding": "3.14",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionStartIncluding": "3.10.51",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionStartIncluding": "3.12.40",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: skbuff: don\u0027t skb_tx_error() the source skb in skb_zerocopy()\n\nskb_zerocopy() copies frags from @from into @to. On an\nskb_orphan_frags() failure it calls skb_tx_error(@from), a destructive\noperation on the source skb the copy helper does not own. That completes\n@from\u0027s zerocopy uarg and clears SKBFL_ALL_ZEROCOPY, including the\nSKBFL_SHARED_FRAG page-ownership marker.\n\nBoth callers already report the failure on their own drop path.\nnfnetlink_queue does it at nla_put_failure, and Open vSwitch does it in\nthe flow-miss drop arm of ovs_dp_process_packet(), so nothing is lost by\ndropping it here.\n\nOn Open vSwitch\u0027s OVS_ACTION_ATTR_USERSPACE path the skb is not freed on\nthis error: do_execute_actions() ignores output_userspace()\u0027s return\nvalue and, unless the upcall was the last action, keeps forwarding the\nsame skb through the flow\u0027s remaining actions. The uarg is completed\nwhile that skb is still in flight, telling the producer its buffers are\nfree, and SKBFL_SHARED_FRAG is cleared on an skb the rest of the stack\nstill handles. That flag is what makes esp_input() call skb_cow_data()\ninstead of decrypting in place, so a later local ESP delivery can\ndecrypt over frags the skb does not own privately.\n\nLeave error reporting to the callers."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 9.3,
            "baseSeverity": "CRITICAL",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:L - skb_zerocopy() only skb_tx_error()s the source when skb_orphan_frags() fails, which requires a still-attached zerocopy uarg without SKBFL_DONT_ORPHAN (vhost-net, xen-netback, AF_PACKET mmap); ordinary remote NIC packets never carry that uarg.\nAC:L - The attacker drives zerocopy TX and can fail skb_copy_ubufs() without an uncontrolled race (non-last OVS OUTPUT clones the skb so skb_shared() is set, or induced GFP_ATOMIC pressure); do_execute_actions() ignores the USERSPACE error and keeps forwarding.\nPR:N - A KVM/Xen guest using vhost-net or xen-netback needs no host account, capability, or /dev/vhost-net fd\u2014only virtio/netback TX on the provisioned vNIC.\nUI:N - Guest or local zerocopy TX and in-kernel OVS USERSPACE-then-forward processing run without the victim mounting, opening a file, or otherwise interacting.\nS:C - vhost-net and xen-netback are host/Dom0 kernel code on the guest NIC boundary; premature uarg completion and SKBFL_SHARED_FRAG removal run in host context from guest zerocopy TX, impacting host kernel state outside the guest authority.\nC:H - skb_tx_error() completes the uarg while the skb is still forwarded and clears SKBFL_SHARED_FRAG, so later esp_input() skips skb_cow_data() and decrypts in place over producer-reused frags, a UAF/in-place primitive that can disclose host-held page contents.\nI:H - In-place ESP decrypt over frags the skb does not own privately, plus premature zerocopy completion, writes attacker-influenced data into pages still referenced by the in-flight host skb, a write primitive suitable for integrity compromise and control-flow impact.\nA:H - Reuse of zerocopy pages still referenced by the forwarded skb, and in-place overwrites of those pages, cause host oopses and panics that can be retriggered from guest or local TX until the host is unavailable."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-09-16T14:42:05.924Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/849bdb83123760a865bcb2970127f4c0b9423ba3"
        },
        {
          "url": "https://git.kernel.org/stable/c/fb10e0e9b220a2eed08931a60dbaad9a2370c908"
        },
        {
          "url": "https://git.kernel.org/stable/c/767ec2a65cc022d303b0c9c12811e7db22057341"
        },
        {
          "url": "https://git.kernel.org/stable/c/8069643ae64dfdf634b6c78c7f622e5323031436"
        },
        {
          "url": "https://git.kernel.org/stable/c/04dd250a78e268af3e7124beb1dc10ec1dd88d60"
        },
        {
          "url": "https://git.kernel.org/stable/c/a13b1e80e5015cd732440b475c0ef443dc4a2157"
        },
        {
          "url": "https://git.kernel.org/stable/c/bab5a851e44a3601d31f2aa8043f385bb50ac5d9"
        },
        {
          "url": "https://git.kernel.org/stable/c/8ece906150128d5ec2462aabcc978c568433eca4"
        }
      ],
      "title": "net: skbuff: don\u0027t skb_tx_error() the source skb in skb_zerocopy()",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2026-90049",
    "datePublished": "2026-09-16T10:33:45.259Z",
    "dateReserved": "2026-09-11T19:38:34.783Z",
    "dateUpdated": "2026-09-16T14:42:05.924Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "epss": {
      "cve": "CVE-2026-90049",
      "date": "2026-10-02",
      "epss": "0.00196",
      "percentile": "0.08358"
    },
    "nvd": {
      "cve": {
        "affected": [
          {
            "affectedData": [
              {
                "defaultStatus": "unaffected",
                "product": "Linux",
                "programFiles": [
                  "net/core/skbuff.c"
                ],
                "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                "vendor": "Linux",
                "versions": [
                  {
                    "lessThan": "849bdb83123760a865bcb2970127f4c0b9423ba3",
                    "status": "affected",
                    "version": "36d5fe6a000790f56039afe26834265db0a3ad4c",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "fb10e0e9b220a2eed08931a60dbaad9a2370c908",
                    "status": "affected",
                    "version": "36d5fe6a000790f56039afe26834265db0a3ad4c",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "767ec2a65cc022d303b0c9c12811e7db22057341",
                    "status": "affected",
                    "version": "36d5fe6a000790f56039afe26834265db0a3ad4c",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "8069643ae64dfdf634b6c78c7f622e5323031436",
                    "status": "affected",
                    "version": "36d5fe6a000790f56039afe26834265db0a3ad4c",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "04dd250a78e268af3e7124beb1dc10ec1dd88d60",
                    "status": "affected",
                    "version": "36d5fe6a000790f56039afe26834265db0a3ad4c",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "a13b1e80e5015cd732440b475c0ef443dc4a2157",
                    "status": "affected",
                    "version": "36d5fe6a000790f56039afe26834265db0a3ad4c",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "bab5a851e44a3601d31f2aa8043f385bb50ac5d9",
                    "status": "affected",
                    "version": "36d5fe6a000790f56039afe26834265db0a3ad4c",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "8ece906150128d5ec2462aabcc978c568433eca4",
                    "status": "affected",
                    "version": "36d5fe6a000790f56039afe26834265db0a3ad4c",
                    "versionType": "git"
                  },
                  {
                    "status": "affected",
                    "version": "c5f0c0e7525443add533495e93ba8de6feab2396",
                    "versionType": "git"
                  },
                  {
                    "status": "affected",
                    "version": "1674b4bf3eea3cac51b70778e89f8025f7cfe695",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "3.11",
                    "status": "affected",
                    "version": "3.10.51",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "3.13",
                    "status": "affected",
                    "version": "3.12.40",
                    "versionType": "semver"
                  }
                ]
              },
              {
                "defaultStatus": "affected",
                "product": "Linux",
                "programFiles": [
                  "net/core/skbuff.c"
                ],
                "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                "vendor": "Linux",
                "versions": [
                  {
                    "status": "affected",
                    "version": "3.14"
                  },
                  {
                    "lessThan": "3.14",
                    "status": "unaffected",
                    "version": "0",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "5.10.*",
                    "status": "unaffected",
                    "version": "5.10.270",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "5.15.*",
                    "status": "unaffected",
                    "version": "5.15.221",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "6.1.*",
                    "status": "unaffected",
                    "version": "6.1.188",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "6.6.*",
                    "status": "unaffected",
                    "version": "6.6.157",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "6.12.*",
                    "status": "unaffected",
                    "version": "6.12.110",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "6.18.*",
                    "status": "unaffected",
                    "version": "6.18.51",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "7.2.*",
                    "status": "unaffected",
                    "version": "7.2.5",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "*",
                    "status": "unaffected",
                    "version": "7.3-rc1",
                    "versionType": "original_commit_for_fix"
                  }
                ]
              }
            ],
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
          }
        ],
        "cveTags": [],
        "descriptions": [
          {
            "lang": "en",
            "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: skbuff: don\u0027t skb_tx_error() the source skb in skb_zerocopy()\n\nskb_zerocopy() copies frags from @from into @to. On an\nskb_orphan_frags() failure it calls skb_tx_error(@from), a destructive\noperation on the source skb the copy helper does not own. That completes\n@from\u0027s zerocopy uarg and clears SKBFL_ALL_ZEROCOPY, including the\nSKBFL_SHARED_FRAG page-ownership marker.\n\nBoth callers already report the failure on their own drop path.\nnfnetlink_queue does it at nla_put_failure, and Open vSwitch does it in\nthe flow-miss drop arm of ovs_dp_process_packet(), so nothing is lost by\ndropping it here.\n\nOn Open vSwitch\u0027s OVS_ACTION_ATTR_USERSPACE path the skb is not freed on\nthis error: do_execute_actions() ignores output_userspace()\u0027s return\nvalue and, unless the upcall was the last action, keeps forwarding the\nsame skb through the flow\u0027s remaining actions. The uarg is completed\nwhile that skb is still in flight, telling the producer its buffers are\nfree, and SKBFL_SHARED_FRAG is cleared on an skb the rest of the stack\nstill handles. That flag is what makes esp_input() call skb_cow_data()\ninstead of decrypting in place, so a later local ESP delivery can\ndecrypt over frags the skb does not own privately.\n\nLeave error reporting to the callers."
          },
          {
            "lang": "es",
            "value": "En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta:\n\nnet: skbuff: no llamar a skb_tx_error() al skb de origen en skb_zerocopy()\n\nskb_zerocopy() copia fragmentos de @from a @to. En caso de fallo de skb_orphan_frags(), llama a skb_tx_error(@from), una operaci\u00f3n destructiva en el skb de origen que el ayudante de copia no posee. Eso completa el uarg de zerocopy de @from y borra SKBFL_ALL_ZEROCOPY, incluyendo el marcador de propiedad de p\u00e1gina SKBFL_SHARED_FRAG.\n\nAmbos llamadores ya informan del fallo en su propia ruta de descarte. nfnetlink_queue lo hace en nla_put_failure, y Open vSwitch lo hace en el brazo de descarte por fallo de flujo de ovs_dp_process_packet(), por lo que no se pierde nada al descartarlo aqu\u00ed.\n\nEn la ruta OVS_ACTION_ATTR_USERSPACE de Open vSwitch, el skb no se libera en este error: do_execute_actions() ignora el valor de retorno de output_userspace() y, a menos que la llamada ascendente fuera la \u00faltima acci\u00f3n, sigue reenviando el mismo skb a trav\u00e9s de las acciones restantes del flujo. El uarg se completa mientras ese skb todav\u00eda est\u00e1 en tr\u00e1nsito, indicando al productor que sus b\u00faferes est\u00e1n libres, y SKBFL_SHARED_FRAG se borra en un skb que el resto de la pila a\u00fan maneja. Esa bandera es lo que hace que esp_input() llame a skb_cow_data() en lugar de descifrar in situ, para que una entrega ESP local posterior pueda descifrar sobre fragmentos que el skb no posee de forma privada.\n\nDejar el informe de errores a los llamadores."
          }
        ],
        "id": "CVE-2026-90049",
        "lastModified": "2026-09-28T23:10:00.143",
        "metrics": {
          "cvssMetricV31": [
            {
              "cvssData": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 9.3,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
                "version": "3.1"
              },
              "exploitabilityScore": 2.5,
              "impactScore": 6.0,
              "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
              "type": "Secondary"
            }
          ]
        },
        "published": "2026-09-16T11:17:18.263",
        "references": [
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/04dd250a78e268af3e7124beb1dc10ec1dd88d60"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/767ec2a65cc022d303b0c9c12811e7db22057341"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/8069643ae64dfdf634b6c78c7f622e5323031436"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/849bdb83123760a865bcb2970127f4c0b9423ba3"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/8ece906150128d5ec2462aabcc978c568433eca4"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/a13b1e80e5015cd732440b475c0ef443dc4a2157"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/bab5a851e44a3601d31f2aa8043f385bb50ac5d9"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/fb10e0e9b220a2eed08931a60dbaad9a2370c908"
          }
        ],
        "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "vulnStatus": "Received"
      }
    }
  }
}



Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Forecast uses a logistic model when the trend is rising, or an exponential decay model when the trend is falling. Fitted via linearized least squares.

Sightings

Author Source Type Date Other

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or observed by the user.
  • Confirmed: The vulnerability has been validated from an analyst's perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
  • Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
  • Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
  • Not confirmed: The user expressed doubt about the validity of the vulnerability.
  • Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.

Loading…

Loading…

Loading…

Related by attack behaviour

Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.


Loading…