Executive brief
A vulnerability in the Linux kernel's networking subsystem could allow a local user to gain full administrative (root) control over the system. The issue occurs when the system handles certain types of high-efficiency network data transfers, leading to a memory error. An attacker can exploit this flaw to bypass security boundaries and compromise the entire operating system.
Technical details
A use-after-free (UAF) vulnerability exists in the Linux kernel's net/core/skbuff.c within the pskb_carve_inside_header() and pskb_carve_inside_nonlinear() helper functions. These functions use memcpy() to copy skb_shared_info but fail to call net_zcopy_get() to increment the reference count for MSG_ZEROCOPY skbs. This leads to a premature free of the ubuf_info_msgzc structure while active TX skbs still hold pointers to it. A local unprivileged attacker can trigger this condition to achieve reliable root privilege escalation. Patches have been released across multiple stable kernel branches to ensure net_zcopy_get() is called during the carve operations.
Affected products
- Linux Linux Kernel Fixed in various stable branches including 2.6.x, 4.x, 5.x, 6.x, and 7.x
Timeline
- 2026-05-26: other: Vulnerability fixed in source code
- 2026-06-24: advisory: NVD publication date
References
- https://git.kernel.org/stable/c/2e0e74c59b2761a414d9f48d7bee1e45220b2427
- https://git.kernel.org/stable/c/474d6c771d798bca84f0a140b611e36743511e18
- https://git.kernel.org/stable/c/8dbed691e43a50903658130bde0fcb5abc425b37
- https://git.kernel.org/stable/c/96a4713ae041cc85e712bac682cd2e644004d6c6
- https://git.kernel.org/stable/c/98d0912e9f841e5529a5b89a972805f34cb1c69d
- https://git.kernel.org/stable/c/9b40bdc2a3298225dffab8158208a0d8c6300578
- https://git.kernel.org/stable/c/ceafb893b12f23331dcc5ff9587e643c3a40ee9f