CVE-2026-46323

Severity CVSS v4.0:
Pending analysis
Type:
CWE-416 Use After Free
Publication date:
09/06/2026
Last modified:
23/07/2026

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> net: gro: don&amp;#39;t merge zcopy skbs<br /> <br /> skb_gro_receive() can currently copy frags between the source and GRO<br /> skb, without checking the zerocopy status, and in particular the<br /> SKBFL_MANAGED_FRAG_REFS flag.<br /> <br /> When SKBFL_MANAGED_FRAG_REFS is set, the skb doesn&amp;#39;t hold a reference<br /> on the pages in shinfo-&gt;frags. Appending those frags to another skb&amp;#39;s<br /> frags without fixing up the page refcount can lead to UAF.<br /> <br /> When either the last skb in the GRO chain (the one we would append<br /> frags to) or the source skb is zerocopy, don&amp;#39;t merge the skbs.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.0 (including) 6.1.176 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.2 (including) 6.6.142 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.7 (including) 6.12.92 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.13 (including) 6.18.34 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.19 (including) 7.0.11 (excluding)
cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:*