openvswitch: only skb_tx_error() a packet we are about to drop
Summary
| CVE | CVE-2026-89487 |
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-11 20:19:30 UTC |
| Updated | 2026-09-11 20:19:30 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved:
openvswitch: only skb_tx_error() a packet we are about to drop
queue_userspace_packet() borrows the packet skb -- it only copies it into
a private netlink message (user_skb) and does not own it; on return
do_execute_actions() keeps forwarding it through the flow's remaining
actions. Its error path nevertheless calls skb_tx_error(skb), which via
skb_zcopy_clear() does skb_shinfo(skb)->flags &= ~SKBFL_ALL_ZEROCOPY,
stripping SKBFL_SHARED_FRAG from that live skb (skb_tx_error()'s kerneldoc
says "skb must be freed afterwards").
For a MSG_ZEROCOPY skb carrying page-cache frags, SKBFL_SHARED_FRAG is
what makes esp_input() skb_cow_data() before in-place AEAD; once it is
stripped a later local ESP-in-UDP delivery decrypts in place over pages
the sender does not own -- an unprivileged page-cache write (the
"Fragnesia" primitive).
do_execute_actions() ignores output_userspace()'s return value, so any
action after a failed USERSPACE upcall inherits the stripped skb.
Move the skb_tx_error() to the flow-miss drop path - the "default"
branch of ovs_dp_process_packet()'s switch(error), before kfree_skb().
The call has been here since commit 36d5fe6a0007 ("core, nfqueue,
openvswitch: Orphan frags in skb_zerocopy and handle errors") but was
harmless until esp_input() began relying on SKBFL_SHARED_FRAG to gate
in-place decrypt; only then did stripping it on a still-forwarded skb
become a page-cache write primitive. |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|
| CNA |
Linux |
Linux |
affected 36d5fe6a000790f56039afe26834265db0a3ad4c 6767d70cf46f65807a6a4c4406a518e6c12e36ae git |
Not specified |
| CNA |
Linux |
Linux |
affected 36d5fe6a000790f56039afe26834265db0a3ad4c e41a59fc056f63a7a1f42788913c53cc48d744aa git |
Not specified |
| CNA |
Linux |
Linux |
affected 36d5fe6a000790f56039afe26834265db0a3ad4c 5d85eef222cfd28e73deed7402c100229e8b9e6e git |
Not specified |
| CNA |
Linux |
Linux |
affected 36d5fe6a000790f56039afe26834265db0a3ad4c 0dbc2398fca3bb33eda963849f865ddb1b3aa05e git |
Not specified |
| CNA |
Linux |
Linux |
affected c5f0c0e7525443add533495e93ba8de6feab2396 git |
Not specified |
| CNA |
Linux |
Linux |
affected 1674b4bf3eea3cac51b70778e89f8025f7cfe695 git |
Not specified |
| CNA |
Linux |
Linux |
affected 3.10.51 3.11 semver |
Not specified |
| CNA |
Linux |
Linux |
affected 3.12.40 3.13 semver |
Not specified |
| CNA |
Linux |
Linux |
affected 3.14 |
Not specified |
| CNA |
Linux |
Linux |
unaffected 3.14 semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.12.109 6.12.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.18.50 6.18.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.2.4 7.2.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.3-rc1 * original_commit_for_fix |
Not specified |
References
| Reference | Source | Link | Tags |
|---|
| git.kernel.org/stable/c/6767d70cf46f65807a6a4c4406a518e6c12e36ae |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/5d85eef222cfd28e73deed7402c100229e8b9e6e |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/0dbc2398fca3bb33eda963849f865ddb1b3aa05e |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/e41a59fc056f63a7a1f42788913c53cc48d744aa |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.