xdp: reject clones that overrun skb_shared_info tailroom
Summary
| CVE | CVE-2026-74616 |
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-22 16:16:34 UTC |
| Updated | 2026-08-22 16:16:34 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved:
xdp: reject clones that overrun skb_shared_info tailroom
xdpf_clone() clones broadcast copies into a single page and sets
frame_sz to PAGE_SIZE. __xdp_build_skb_from_frame() later treats that
page like a normal XDP frame and expects the usual skb_shared_info
tailroom at the end of the buffer.
The current check only rejects frames whose linear xdp_frame header,
headroom, and packet data exceed PAGE_SIZE. A source frame backed by a
larger allocation can still satisfy that check while extending into the
clone's required shared-info area. When such a clone is converted back
into an skb, build_skb_around() places skb_shared_info over live packet
bytes and later writes can corrupt XDP return metadata.
Reject clones unless their linear area fits inside
SKB_WITH_OVERHEAD(PAGE_SIZE), matching the tailroom requirement already
enforced by the XDP-to-skb conversion path. |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|
| CNA |
Linux |
Linux |
affected e624d4ed4aa8cc3c69d1359b0aaea539203ed266 58408982fa39f9758124cec169f42854d6f98f35 git |
Not specified |
| CNA |
Linux |
Linux |
affected e624d4ed4aa8cc3c69d1359b0aaea539203ed266 685edea27ac68d08fe4dbd3de74b858d2ad8e830 git |
Not specified |
| CNA |
Linux |
Linux |
affected e624d4ed4aa8cc3c69d1359b0aaea539203ed266 ba13763d667e008e185fedf592d53846a5b457d1 git |
Not specified |
| CNA |
Linux |
Linux |
affected e624d4ed4aa8cc3c69d1359b0aaea539203ed266 ef4b7c7046d29a67090de15af0da0d1ae8d1b192 git |
Not specified |
| CNA |
Linux |
Linux |
affected e624d4ed4aa8cc3c69d1359b0aaea539203ed266 fab820f1691a9e26d9031f18aae1e9ce09078f92 git |
Not specified |
| CNA |
Linux |
Linux |
affected e624d4ed4aa8cc3c69d1359b0aaea539203ed266 f463b6f4957c9c3fd1c75f8d3e5af4879fa609c0 git |
Not specified |
| CNA |
Linux |
Linux |
affected e624d4ed4aa8cc3c69d1359b0aaea539203ed266 e48e8edbef2eb824201495daa5234560f632b23c git |
Not specified |
| CNA |
Linux |
Linux |
affected 5.14 |
Not specified |
| CNA |
Linux |
Linux |
unaffected 5.14 semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 5.15.216 5.15.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.1.183 6.1.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.6.152 6.6.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.12.104 6.12.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.18.45 6.18.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.1.9 7.1.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.2 * original_commit_for_fix |
Not specified |
References
| Reference | Source | Link | Tags |
|---|
| git.kernel.org/stable/c/e48e8edbef2eb824201495daa5234560f632b23c |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/58408982fa39f9758124cec169f42854d6f98f35 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/685edea27ac68d08fe4dbd3de74b858d2ad8e830 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/fab820f1691a9e26d9031f18aae1e9ce09078f92 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/ef4b7c7046d29a67090de15af0da0d1ae8d1b192 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/ba13763d667e008e185fedf592d53846a5b457d1 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/f463b6f4957c9c3fd1c75f8d3e5af4879fa609c0 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.