← All Advisories

CVE-2026-98368

Last refreshed2026-10-09

Status: UPDATED  |  Advisory ID: CVE-2026-98368

Key Details

CVECVE-2026-98368
CVSS Score / Version7.8 (High) / CVSS v3.1
Updated2026-10-07
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is local; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsLinux Kernel

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux Kernel
SubsystemsOT Supporting Infrastructure
SectorsAll Sectors

What to Know

In the Linux kernel, the following vulnerability has been resolved:

esp: downgrade zerocopy managed frags before mutating skb frags

On the out-of-place output path (esp->inplace == false) ESP rewrites the

skb frag array: esp_output_head() appends a trailer frag and

esp_output_tail() replaces the frags with a destination page, both

referenced with get_page().

When the skb carries zerocopy managed frags (SKBFL_MANAGED_FRAG_REFS) the

payload frags are owned by the ubuf and must not be referenced or

unreferenced individually, but ESP mutates the frag array without ever

downgrading the skb. This breaks the managed-frag invariant two ways:

- esp_ssg_unref() walks the source scatterlist and drops a page

reference for every frag, including the ubuf-owned payload frags,

pushing their refcount below the GUP pin bias while the pages are

still pinned, i.e. a use-after-free of the zerocopy pages;

- esp_output_tail() installs its destination page as frag 0 with

get_page() but leaves SKBFL_MANAGED_FRAG_REFS set, so

skb_release_data() takes the skip_unref branch and never drops that

reference, leaking the x->xfrag page at packet rate.

Fix this the way every other frag-mutating site does (__ip_append_data(),

__ip6_append_data(), tcp_sendmsg_locked()) and call

skb_zcopy_downgrade_managed() before ESP touches the frag array: it takes

a real reference on each existing frag and clears SKBFL_MANAGED_FRAG_REFS,

so the per-frag unref in esp_ssg_unref() and the frag release in

skb_release_data() are both balanced and no mixed-ownership frag array is

left behind. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-98368
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-98368