Junglewise Threat Intelligence

CVE-2026-80590: Linux kernel GSO state handling flaw in fragment reassembly

CVE-2026-80590 · Severity: high · CVSS 8.6 · Published 2026-08-28

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's packet reassembly logic fails to strip generic segmentation offload (GSO) metadata from fragments before combining them. An attacker can craft specially formed network packets to trigger a kernel panic, causing the system to crash and become unavailable. This can be exploited by unprivileged users or over the network on vulnerable configurations.

Technical details

The vulnerability exists in the inet_frag_reasm_prepare()/inet_frag_reasm_finish() functions which preserve GSO state (gso_size, gso_type, gso_segs) from the first fragment when reassembling fragmented IP packets. When the reassembled datagram is later processed by software segmentation points (udp_rcv_segment(), validate_xmit_skb(), ip_finish_output_gso()), the skb_segment() function's frag_list walk assumes GRO-shaped input and triggers a BUG_ON() assertion. An unprivileged user can exploit this via tap/tun interfaces or AF_PACKET with PACKET_VNET_HDR by writing two specially crafted IPv4 or IPv6 fragments with GSO headers. The fix clears GSO fields for every fragment in inet_frag_queue_insert(), which is shared by IPv4, IPv6, nf_conntrack_reasm, and 6lowpan reassembly paths. A patch is available.

Affected products

  • Linux Linux kernel since commit f43798c27684 (tun: Allow GSO using virtio_net_hdr); affecting net.git and stable branches

Timeline

  • 2026-08-28: disclosed
  • 2026-08-28: advisory: CVE-2026-80590 assigned

Related threats