{"api_version":"1","generated_at":"2026-09-14T08:03:49+00:00","cve":"CVE-2026-80977","urls":{"html":"https://cve.report/CVE-2026-80977","api":"https://cve.report/api/cve/CVE-2026-80977.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-80977","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-80977"},"summary":{"title":"net: skbuff: don't touch shared zerocopy state in skb_tx_error()","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: skbuff: don't touch shared zerocopy state in skb_tx_error()\n\nskb_tx_error() completes the zerocopy uarg and clears\nSKBFL_ALL_ZEROCOPY, and skb_zcopy_downgrade_managed() clears\nSKBFL_MANAGED_FRAG_REFS. Both live in skb_shinfo(), which every clone\nshares, while the caller only owns the reference it is about to drop.\nThrough a clone it tells the producer its pages are free and drops\nSKBFL_SHARED_FRAG for an skb that is still in flight.\n\nOpen vSwitch reaches this with a non-last OVS_ACTION_ATTR_RECIRC:\nclone_execute() sends a skb_clone() into ovs_dp_process_packet() while\ndo_execute_actions() keeps forwarding the original, and skb_clone()\ndoes not privatise the frags here -- skb_orphan_frags() returns early\non SKBFL_DONT_ORPHAN. A flow miss on the clone then strips the marker\nfrom the packet still being forwarded, and a later local ESP delivery\ndecrypts in place over frags it does not own privately.\n\nSkip it for a cloned skb. Nothing is lost: skb_release_data() clears\nthe zerocopy state once the last reference to the shared data goes.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-09-11 20:19:04","updated_at":"2026-09-13 07:17:04"},"problem_types":[],"metrics":[{"version":"3.1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","score":"7.8","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"7.8","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","data":{"baseScore":7.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}}],"references":[{"url":"https://git.kernel.org/stable/c/f66bdb1cc0fcd227a062378f8be0b5873aa5600a","name":"https://git.kernel.org/stable/c/f66bdb1cc0fcd227a062378f8be0b5873aa5600a","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/0370da114a9bc044e248b85c6809d1b5e0c1f7f9","name":"https://git.kernel.org/stable/c/0370da114a9bc044e248b85c6809d1b5e0c1f7f9","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/288f9970670841044ab030104fa6b6ed159949d0","name":"https://git.kernel.org/stable/c/288f9970670841044ab030104fa6b6ed159949d0","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/15aa81b390d401abf4b8211042470e9e92e3b7fb","name":"https://git.kernel.org/stable/c/15aa81b390d401abf4b8211042470e9e92e3b7fb","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-80977","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-80977","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 25121173f7b1e4ac3fc692df6e7b8c52ec36abba 15aa81b390d401abf4b8211042470e9e92e3b7fb git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 25121173f7b1e4ac3fc692df6e7b8c52ec36abba 288f9970670841044ab030104fa6b6ed159949d0 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 25121173f7b1e4ac3fc692df6e7b8c52ec36abba 0370da114a9bc044e248b85c6809d1b5e0c1f7f9 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 25121173f7b1e4ac3fc692df6e7b8c52ec36abba f66bdb1cc0fcd227a062378f8be0b5873aa5600a git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 3.8","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 3.8 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.12.109 6.12.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.50 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2.4 7.2.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.3-rc1 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"80977","cve":"CVE-2026-80977","epss":"0.001280000","percentile":"0.028170000","score_date":"2026-09-13","updated_at":"2026-09-14 00:18:01"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["net/core/skbuff.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"15aa81b390d401abf4b8211042470e9e92e3b7fb","status":"affected","version":"25121173f7b1e4ac3fc692df6e7b8c52ec36abba","versionType":"git"},{"lessThan":"288f9970670841044ab030104fa6b6ed159949d0","status":"affected","version":"25121173f7b1e4ac3fc692df6e7b8c52ec36abba","versionType":"git"},{"lessThan":"0370da114a9bc044e248b85c6809d1b5e0c1f7f9","status":"affected","version":"25121173f7b1e4ac3fc692df6e7b8c52ec36abba","versionType":"git"},{"lessThan":"f66bdb1cc0fcd227a062378f8be0b5873aa5600a","status":"affected","version":"25121173f7b1e4ac3fc692df6e7b8c52ec36abba","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["net/core/skbuff.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"3.8"},{"lessThan":"3.8","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"6.12.*","status":"unaffected","version":"6.12.109","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.50","versionType":"semver"},{"lessThanOrEqual":"7.2.*","status":"unaffected","version":"7.2.4","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.3-rc1","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.12.109","versionStartIncluding":"3.8","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.50","versionStartIncluding":"3.8","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2.4","versionStartIncluding":"3.8","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.3-rc1","versionStartIncluding":"3.8","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: skbuff: don't touch shared zerocopy state in skb_tx_error()\n\nskb_tx_error() completes the zerocopy uarg and clears\nSKBFL_ALL_ZEROCOPY, and skb_zcopy_downgrade_managed() clears\nSKBFL_MANAGED_FRAG_REFS. Both live in skb_shinfo(), which every clone\nshares, while the caller only owns the reference it is about to drop.\nThrough a clone it tells the producer its pages are free and drops\nSKBFL_SHARED_FRAG for an skb that is still in flight.\n\nOpen vSwitch reaches this with a non-last OVS_ACTION_ATTR_RECIRC:\nclone_execute() sends a skb_clone() into ovs_dp_process_packet() while\ndo_execute_actions() keeps forwarding the original, and skb_clone()\ndoes not privatise the frags here -- skb_orphan_frags() returns early\non SKBFL_DONT_ORPHAN. A flow miss on the clone then strips the marker\nfrom the packet still being forwarded, and a later local ESP delivery\ndecrypts in place over frags it does not own privately.\n\nSkip it for a cloned skb. Nothing is lost: skb_release_data() clears\nthe zerocopy state once the last reference to the shared data goes."}],"metrics":[{"cvssV3_1":{"baseScore":7.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"scenarios":[{"lang":"en","value":"AV:L - The buggy state is a locally originated MSG_ZEROCOPY/io_uring TX skb (SKBFL_DONT_ORPHAN plus a uarg); NIC-received packets never carry that marker, and the skb must still be forwarded into local ESP, so a local account is required.\nAC:L - The attacker fully controls both sides: OVS flows with a non-last RECIRC, a guaranteed miss/upcall failure on the clone, MSG_ZEROCOPY send, and the ESP SA/payload, so the shared-shinfo strip and in-place decrypt are reliably reproducible with no race beyond attacker influence.\nPR:L - An unprivileged user can enable SO_ZEROCOPY and, via unshare -Urn, obtain CAP_NET_ADMIN in a user+net namespace; OVS genetlink uses GENL_UNS_ADMIN_PERM and XFRM SAs are likewise namespace-installable, while the global page cache remains the corruption target.\nUI:N - The attacker installs the OVS recirc flow, sends the MSG_ZEROCOPY packet, and completes local ESP delivery without any victim action.\nS:U - The resulting page-cache write and premature zerocopy completion stay inside the host kernel's memory authority as a standard local memory-corruption/LPE primitive and do not cross a VM or IOMMU boundary.\nC:H - skb_tx_error() on the clone completes the shared uarg and clears SKBFL_SHARED_FRAG, so later in-place ESP decrypt (and UAF of still-mapped pages) corrupts globally cached file/code pages and can be leveraged for arbitrary disclosure.\nI:H - With the shared-frag marker stripped, esp_input() skips skb_cow_data() and AEAD-decrypts attacker-controlled plaintext in place over page-cache-backed frags, yielding an unprivileged write into files the sender could only read (the Fragnesia primitive).\nA:H - Use-after-free of zerocopy pages still referenced by the in-flight original skb, plus overwriting page-cache-backed executable or kernel-managed data, causes oopses, panics, and process crashes."}]}],"providerMetadata":{"dateUpdated":"2026-09-13T06:28:43.038Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/15aa81b390d401abf4b8211042470e9e92e3b7fb"},{"url":"https://git.kernel.org/stable/c/288f9970670841044ab030104fa6b6ed159949d0"},{"url":"https://git.kernel.org/stable/c/0370da114a9bc044e248b85c6809d1b5e0c1f7f9"},{"url":"https://git.kernel.org/stable/c/f66bdb1cc0fcd227a062378f8be0b5873aa5600a"}],"title":"net: skbuff: don't touch shared zerocopy state in skb_tx_error()","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-80977","datePublished":"2026-09-11T19:42:38.862Z","dateReserved":"2026-08-26T14:34:25.811Z","dateUpdated":"2026-09-13T06:28:43.038Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-11 20:19:04","lastModifiedDate":"2026-09-13 07:17:04","problem_types":[],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"80977","Ordinal":"1","Title":"net: skbuff: don't touch shared zerocopy state in skb_tx_error()","CVE":"CVE-2026-80977","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"80977","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: skbuff: don't touch shared zerocopy state in skb_tx_error()\n\nskb_tx_error() completes the zerocopy uarg and clears\nSKBFL_ALL_ZEROCOPY, and skb_zcopy_downgrade_managed() clears\nSKBFL_MANAGED_FRAG_REFS. Both live in skb_shinfo(), which every clone\nshares, while the caller only owns the reference it is about to drop.\nThrough a clone it tells the producer its pages are free and drops\nSKBFL_SHARED_FRAG for an skb that is still in flight.\n\nOpen vSwitch reaches this with a non-last OVS_ACTION_ATTR_RECIRC:\nclone_execute() sends a skb_clone() into ovs_dp_process_packet() while\ndo_execute_actions() keeps forwarding the original, and skb_clone()\ndoes not privatise the frags here -- skb_orphan_frags() returns early\non SKBFL_DONT_ORPHAN. A flow miss on the clone then strips the marker\nfrom the packet still being forwarded, and a later local ESP delivery\ndecrypts in place over frags it does not own privately.\n\nSkip it for a cloned skb. Nothing is lost: skb_release_data() clears\nthe zerocopy state once the last reference to the shared data goes.","Type":"Description","Title":"net: skbuff: don't touch shared zerocopy state in skb_tx_error()"}]}}}