openvswitch: only skb_tx_error() a packet we are about to drop
Summary
| CVE | CVE-2026-89487 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-11 20:19:30 UTC |
| Updated | 2026-09-14 13:19:05 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: openvswitch: only skb_tx_error() a packet we are about to drop queue_userspace_packet() borrows the packet skb -- it only copies it into a private netlink message (user_skb) and does not own it; on return do_execute_actions() keeps forwarding it through the flow's remaining actions. Its error path nevertheless calls skb_tx_error(skb), which via skb_zcopy_clear() does skb_shinfo(skb)->flags &= ~SKBFL_ALL_ZEROCOPY, stripping SKBFL_SHARED_FRAG from that live skb (skb_tx_error()'s kerneldoc says "skb must be freed afterwards"). For a MSG_ZEROCOPY skb carrying page-cache frags, SKBFL_SHARED_FRAG is what makes esp_input() skb_cow_data() before in-place AEAD; once it is stripped a later local ESP-in-UDP delivery decrypts in place over pages the sender does not own -- an unprivileged page-cache write (the "Fragnesia" primitive). do_execute_actions() ignores output_userspace()'s return value, so any action after a failed USERSPACE upcall inherits the stripped skb. Move the skb_tx_error() to the flow-miss drop path - the "default" branch of ovs_dp_process_packet()'s switch(error), before kfree_skb(). The call has been here since commit 36d5fe6a0007 ("core, nfqueue, openvswitch: Orphan frags in skb_zerocopy and handle errors") but was harmless until esp_input() began relying on SKBFL_SHARED_FRAG to gate in-place decrypt; only then did stripping it on a still-forwarded skb become a page-cache write primitive. |
Risk And Classification
Primary CVSS: v3.1 7.8 HIGH from 416baaa9-dc9f-4396-8d5f-8c081fb06d67
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS: 0.001280000 probability, percentile 0.028310000 (date 2026-09-14)
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | Secondary | 7.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | CNA | DECLARED | 7.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
CVSS v3.1 Breakdown
Attack Vector
LocalAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected 36d5fe6a000790f56039afe26834265db0a3ad4c 5de5d554141a15b3f1f5c978fd9f7f4fd6d0600a git | Not specified |
| CNA | Linux | Linux | affected 36d5fe6a000790f56039afe26834265db0a3ad4c 48db11e115d1b232edc5591604adc6eda95cd545 git | Not specified |
| CNA | Linux | Linux | affected 36d5fe6a000790f56039afe26834265db0a3ad4c 4477222e2916a18e273edc139c955ade6bbb7a69 git | Not specified |
| CNA | Linux | Linux | affected 36d5fe6a000790f56039afe26834265db0a3ad4c 4d5c460ef8754be1d43b16dbf02695b008b207d6 git | Not specified |
| CNA | Linux | Linux | affected 36d5fe6a000790f56039afe26834265db0a3ad4c 6767d70cf46f65807a6a4c4406a518e6c12e36ae git | Not specified |
| CNA | Linux | Linux | affected 36d5fe6a000790f56039afe26834265db0a3ad4c e41a59fc056f63a7a1f42788913c53cc48d744aa git | Not specified |
| CNA | Linux | Linux | affected 36d5fe6a000790f56039afe26834265db0a3ad4c 5d85eef222cfd28e73deed7402c100229e8b9e6e git | Not specified |
| CNA | Linux | Linux | affected 36d5fe6a000790f56039afe26834265db0a3ad4c 0dbc2398fca3bb33eda963849f865ddb1b3aa05e git | Not specified |
| CNA | Linux | Linux | affected c5f0c0e7525443add533495e93ba8de6feab2396 git | Not specified |
| CNA | Linux | Linux | affected 1674b4bf3eea3cac51b70778e89f8025f7cfe695 git | Not specified |
| CNA | Linux | Linux | affected 3.10.51 3.11 semver | Not specified |
| CNA | Linux | Linux | affected 3.12.40 3.13 semver | Not specified |
| CNA | Linux | Linux | affected 3.14 | Not specified |
| CNA | Linux | Linux | unaffected 3.14 semver | Not specified |
| CNA | Linux | Linux | unaffected 5.10.270 5.10.* semver | Not specified |
| CNA | Linux | Linux | unaffected 5.15.221 5.15.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.1.188 6.1.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.6.157 6.6.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.12.109 6.12.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.18.50 6.18.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.2.4 7.2.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.3-rc1 * original_commit_for_fix | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/6767d70cf46f65807a6a4c4406a518e6c12e36ae | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/5d85eef222cfd28e73deed7402c100229e8b9e6e | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/4d5c460ef8754be1d43b16dbf02695b008b207d6 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/5de5d554141a15b3f1f5c978fd9f7f4fd6d0600a | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/0dbc2398fca3bb33eda963849f865ddb1b3aa05e | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/48db11e115d1b232edc5591604adc6eda95cd545 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/4477222e2916a18e273edc139c955ade6bbb7a69 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/e41a59fc056f63a7a1f42788913c53cc48d744aa | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.