Executive brief
A vulnerability was identified in the Linux kernel's networking stack that could lead to system instability or unauthorized memory access. The issue occurs when the system processes network data using a performance-optimizing technique called Generic Receive Offload (GRO). If an attacker sends specific types of network traffic, it could cause the system to reuse memory incorrectly, potentially leading to a system crash or data corruption.
Technical details
A use-after-free (UAF) vulnerability exists in the skb_gro_receive() function within the Linux kernel's networking core. The root cause is a failure to check the zerocopy status, specifically the SKBFL_MANAGED_FRAG_REFS flag, when merging socket buffers (skbs). When this flag is set, the skb does not hold a reference on the pages in its fragments; appending these fragments to another skb without incrementing the page reference count leads to a UAF condition. The fix prevents merging when either the source or destination skb is a zerocopy buffer. Patches have been backported to various stable kernel branches.
Affected products
- Linux Linux Kernel versions prior to 6.10-rc1
Timeline
- 2026-05-20: disclosed: Initial patch authored
- 2026-06-01: patched: Commits merged into stable trees
- 2026-06-09: advisory: CVE published
References
- https://git.kernel.org/stable/c/1f9c828556416fbe3f49386708ce999fc4d4da06
- https://git.kernel.org/stable/c/44bea2032af0425e4ce6d26a8af0ede79db49ec1
- https://git.kernel.org/stable/c/479084ae0e1d9cb7929cb4298d35623de189f80a
- https://git.kernel.org/stable/c/4db79a322db8c97f7b73b8a347395ef4d685eb40
- https://git.kernel.org/stable/c/e334cbf3388fd9334503a778a82d9e9f14dd2f71