Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-98368— esp: downgrade zerocopy managed frags before mutating skb frags

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Linux 内核中,以下漏洞已修复: ESP:在修改 skb 碎片前,先降级零拷贝管理的碎片 在非原位输出路径(即 )中,ESP 会重写 skb 的碎片数组: 附加一个 trailer 碎片,而 则用目标页面替换原有碎片,两者均通过 增加引用计数。 当 skb 包含由用户缓冲区(ubuf)管理的零拷贝碎片(标记为 )时,载荷碎片归 ubuf 所有,不应单独增加或减少其引用计数。然而,ESP 在未先将 skb 降级为非管理碎片的情况下直接修改了碎片数组,从而以两种破坏方式违背了“管理碎片”的不变量约束: 遍历源分

CVSS 7.8 · High EPSS 0.13% · P2

Affected Version Matrix 14

VendorProduct Version RangeStatus
Linux Linux 753f1ca4e1e50248a1b760c9774d6d6b354562cc< 2359264f377cdbdef2d95868cc8fb572949e48d3 affected
753f1ca4e1e50248a1b760c9774d6d6b354562cc< 69a768c12398cada8528080332c822623fa7064d affected
753f1ca4e1e50248a1b760c9774d6d6b354562cc< 6508304ac2c8cdafca2f4ab915df8c707893e134 affected
753f1ca4e1e50248a1b760c9774d6d6b354562cc< 6cab554f2c0f28773f712ed3a5479103f42ce844 affected
753f1ca4e1e50248a1b760c9774d6d6b354562cc< 0d0845ee61c5df47cc68bc446501f48f71e8dcc6 affected
753f1ca4e1e50248a1b760c9774d6d6b354562cc< f89416eb3db151170a6f3c6dfc5239d26cdce4d2 affected
6.0 affected
< 6.0 unaffected
… +6 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-98368

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
esp: downgrade zerocopy managed frags before mutating skb frags
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: esp: downgrade zerocopy managed frags before mutating skb frags On the out-of-place output path (esp->inplace == false) ESP rewrites the skb frag array: esp_output_head() appends a trailer frag and esp_output_tail() replaces the frags with a destination page, both referenced with get_page(). When the skb carries zerocopy managed frags (SKBFL_MANAGED_FRAG_REFS) the payload frags are owned by the ubuf and must not be referenced or unreferenced individually, but ESP mutates the frag array without ever downgrading the skb. This breaks the managed-frag invariant two ways: - esp_ssg_unref() walks the source scatterlist and drops a page reference for every frag, including the ubuf-owned payload frags, pushing their refcount below the GUP pin bias while the pages are still pinned, i.e. a use-after-free of the zerocopy pages; - esp_output_tail() installs its destination page as frag 0 with get_page() but leaves SKBFL_MANAGED_FRAG_REFS set, so skb_release_data() takes the skip_unref branch and never drops that reference, leaking the x->xfrag page at packet rate. Fix this the way every other frag-mutating site does (__ip_append_data(), __ip6_append_data(), tcp_sendmsg_locked()) and call skb_zcopy_downgrade_managed() before ESP touches the frag array: it takes a real reference on each existing frag and clears SKBFL_MANAGED_FRAG_REFS, so the per-frag unref in esp_ssg_unref() and the frag release in skb_release_data() are both balanced and no mixed-ownership frag array is left behind.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 753f1ca4e1e50248a1b760c9774d6d6b354562cc ~ 2359264f377cdbdef2d95868cc8fb572949e48d3 -
Linux Linux 6.0 -

II. Public POCs for CVE-2026-98368

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-98368

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-98368 (6)

Same Patch Batch · Linux · 2026-10-06 · 208 CVEs total

CVE-2026-98323 9.8 CRITICAL RDMA/siw: Bound fragmented header copies by the remaining length
CVE-2026-98365 9.8 CRITICAL RDMA/rxe: Fix integer overflow in mr_check_range() leading to OOB access
CVE-2026-98282 8.8 HIGH powerpc/iommu: Fix the overflow validation in iommu_tce_check_ioba
CVE-2026-98339 8.8 HIGH wifi: cfg80211: don't filter by BSS type when removing stale entries
CVE-2026-98171 8.8 HIGH smb: client: fix next_buffer UAF and NextCommand bounds in compound PDUs
CVE-2026-98283 8.8 HIGH KVM: PPC: Book3S HV: fix use-after-free in kvmhv_emulate_tlbie_all_lpid()
CVE-2026-98261 8.1 HIGH cifs: Fix server use-after-free in cifs_chan_skip_or_disable()
CVE-2026-98357 8.1 HIGH IB/isert: wait for deferred control PDU completions before releasing the connection
CVE-2026-98239 8.1 HIGH net: lan743x: fix RX checksum use-after-free
CVE-2026-98341 7.8 HIGH wifi: cfg80211: don't free driver-owned scan requests
CVE-2026-98260 7.8 HIGH exec: Cleanup POSIX timers right after de_thread()
CVE-2026-98281 7.8 HIGH futex: Also allocate private hash on vfork()
CVE-2026-98324 7.8 HIGH dmaengine: pxa: fix double counting of the hw descriptors
CVE-2026-98320 7.8 HIGH netfilter: flowtable: hold reference on ct until flow is released
CVE-2026-98228 7.8 HIGH mips: select CONFIG_WEAK_REORDERING_BEYOND_LLSC from CONFIG_EYEQ
CVE-2026-98229 7.8 HIGH xfrm: save input state data before secpath resets
CVE-2026-98318 7.8 HIGH smb: client: validate absolute native symlink targets before NT fixups
CVE-2026-98256 7.8 HIGH signal: Prevent exec() race
CVE-2026-98253 7.8 HIGH RDMA/ucma: Serialize join and leave on copy_to_user failure
CVE-2026-98254 7.8 HIGH swiotlb: use the adjusted address for the highmem page lookup

Showing top 20 of 208 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-98368

No comments yet


Leave a comment