Junglewise Threat Intelligence

CVE-2026-46300: Linux Kernel out-of-bounds write in skbuff coalescing

CVE-2026-46300 · Severity: high · CVSS 7.8 · Published 2026-05-23

Technologies: Linux Kernel, Google Cloud Platform, Amazon AWS. Vendors: Linux, Google, Amazon.

Executive brief

A vulnerability in the Linux kernel's networking subsystem could allow an attacker to cause data corruption or potentially gain unauthorized access. The issue occurs when the system incorrectly handles shared memory fragments during network data processing, leading to situations where encrypted data might be overwritten or improperly accessed. This affects the integrity and confidentiality of data handled by the system's network stack.

Technical details

A vulnerability exists in the Linux kernel's skbuff management where the skb_try_coalesce() function fails to propagate the SKBFL_SHARED_FRAG (or SKBTX_SHARED_FRAG in older versions) flag when attaching paged fragments. This flag indicates that fragments are externally owned or page-cache-backed. When this marker is lost, subsequent in-place writers—specifically the ESP (Encapsulating Security Payload) input path—may incorrectly assume the data is safe to modify in place. This can result in the kernel decrypting data directly over page-cache backed fragments, leading to an out-of-bounds write (CWE-787) or memory corruption. The issue has been resolved by ensuring the shared-fragment bit is propagated during fragment transfers.

Affected products

  • Linux Linux Kernel 3.9 to 5.10.257, 5.11 to 5.15.208, 5.16 to 6.1.174, 6.2 to 6.6.141, 6.7 to 6.12.91, 6.13 to 6.18.33, 6.19 to 7.0.10

CVE identifiers

  • CVE-2026-46300
  • CVE-2026-43284

Timeline

  • 2026-05-13: disclosed: Vulnerability reported by William Bowling
  • 2026-05-23: patched: Fixes merged into various stable kernel branches
  • 2026-05-23: advisory: Initial NVD publication

References

Related threats