Junglewise Threat Intelligence

CVE-2026-46323: Linux Kernel use-after-free in net GRO during skb merging

CVE-2026-46323 · Severity: info · Published 2026-06-09

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's networking stack that could lead to system instability or unauthorized memory access. The issue occurs when the system processes network data using a performance-optimizing technique called Generic Receive Offload (GRO). If an attacker sends specific types of network traffic, it could cause the system to reuse memory incorrectly, potentially leading to a system crash or data corruption.

Technical details

A use-after-free (UAF) vulnerability exists in the skb_gro_receive() function within the Linux kernel's networking core. The root cause is a failure to check the zerocopy status, specifically the SKBFL_MANAGED_FRAG_REFS flag, when merging socket buffers (skbs). When this flag is set, the skb does not hold a reference on the pages in its fragments; appending these fragments to another skb without incrementing the page reference count leads to a UAF condition. The fix prevents merging when either the source or destination skb is a zerocopy buffer. Patches have been backported to various stable kernel branches.

Affected products

  • Linux Linux Kernel versions prior to 6.10-rc1

Timeline

  • 2026-05-20: disclosed: Initial patch authored
  • 2026-06-01: patched: Commits merged into stable trees
  • 2026-06-09: advisory: CVE published

References

Related threats