Executive brief
The Linux kernel's AF_XDP socket implementation has a flaw in how it handles zero-copy packet transmission when invalid or oversized packets are encountered. When processing batches of network packets, descriptors for incomplete or invalid packets can be lost—neither delivered to the network driver nor returned to the application for reuse. This can cause memory leaks and degrade network performance in AF_XDP-based networking applications.
Technical details
The vulnerability is in the AF_XDP (Address Family XDP) zero-copy transmit batch processing path. When the Tx batch parser encounters an invalid descriptor or a packet exceeding xdp_zc_max_segs, it stops processing without properly tracking which descriptors should be reclaimed. This causes descriptors to be neither submitted to the driver nor returned to userspace via the completion queue (CQ). The fix restructures batch processing to use packet-framed parsing, distinguishes valid from invalid packet descriptors, and ensures invalid or oversized packet descriptors are appended to the CQ for userspace reclamation. The patch also tracks driver-visible CQ entries to maintain completion ordering and prevents descriptor loss in multi-socket shared UMEM scenarios.
Affected products
- Linux Linux kernel <unknown>
Timeline
- 2026-08-15: patched: Patch published in kernel mainline