{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-53216","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-06-09T07:44:35.392Z","datePublished":"2026-06-25T08:39:19.529Z","dateUpdated":"2026-08-05T12:34:12.526Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-05T12:34:12.526Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: mvpp2: limit XDP frame size to the RX buffer\n\nmvpp2 has short and long BM pools, and short pool buffers can be smaller\nthan PAGE_SIZE. The XDP path nevertheless initializes every xdp_buff with\nPAGE_SIZE as frame size.\n\nXDP helpers use frame_sz to validate tail growth and to derive the hard\nend of the data area. Advertising PAGE_SIZE for short buffers can let\nbpf_xdp_adjust_tail() grow a packet past the real allocation, corrupting\nmemory or later tripping skb tailroom checks.\n\nInitialize the XDP buffer with bm_pool->frag_size so XDP tailroom matches\nthe actual buffer backing the packet."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL"},"scenarios":[{"lang":"en","value":"AV:N - The vulnerable mvpp2 RX/XDP path is reached by packets arriving on a network interface, and in a plausible XDP-enabled router/firewall deployment a remote peer can trigger it with crafted traffic.\nAC:L - There is no race; once XDP tail growth is present, packet size and repeated delivery are attacker-controllable and the short-buffer condition is deterministic.\nPR:N - In the highest reasonable deployment, the XDP program is already part of the exposed dataplane, so the packet sender needs no local account or authentication. Administrative privilege is needed to install XDP, but not to trigger the vulnerable receive path.\nUI:N - No victim user action is required after the affected interface and XDP dataplane are running.\nS:U - The corruption occurs within the kernel/network-driver security authority and does not cross a separate boundary such as guest-to-host or IOMMU isolation.\nC:H - This is kernel memory corruption from writing past the real RX buffer; such corruption can reasonably be leveraged for information disclosure.\nI:H - bpf_xdp_adjust_tail() can write beyond the allocated buffer due to the false PAGE_SIZE frame limit, making this an out-of-bounds kernel write.\nA:H - The bug can corrupt adjacent memory or trip skb tailroom checks, making kernel crashes or persistent receive-path failure plausible."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/net/ethernet/marvell/mvpp2/mvpp2_main.c"],"versions":[{"version":"07dd0a7aae7f72af7cec18909581c2bb570edddc","lessThan":"a3ee9231ccec6ec3be2de89c56f897055fd9eab1","status":"affected","versionType":"git"},{"version":"07dd0a7aae7f72af7cec18909581c2bb570edddc","lessThan":"ec8e1e5842bc0dbd4c272761f4db3651eecd0339","status":"affected","versionType":"git"},{"version":"07dd0a7aae7f72af7cec18909581c2bb570edddc","lessThan":"3b8b0c3631b19faee53f0d15a49924129b063eec","status":"affected","versionType":"git"},{"version":"07dd0a7aae7f72af7cec18909581c2bb570edddc","lessThan":"994bd2b58d2bd08aa97ec0836cc813cfcb00d749","status":"affected","versionType":"git"},{"version":"07dd0a7aae7f72af7cec18909581c2bb570edddc","lessThan":"910617a4e67dbdd5fdb39d9dc6a51e491e1b2c3e","status":"affected","versionType":"git"},{"version":"07dd0a7aae7f72af7cec18909581c2bb570edddc","lessThan":"9545cc5ef18ca22d031f2f47c157192460652359","status":"affected","versionType":"git"},{"version":"07dd0a7aae7f72af7cec18909581c2bb570edddc","lessThan":"f3c6aa078927e6fe8121c9c591ddee8716c5305a","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/net/ethernet/marvell/mvpp2/mvpp2_main.c"],"versions":[{"version":"5.9","status":"affected"},{"version":"0","lessThan":"5.9","status":"unaffected","versionType":"semver"},{"version":"5.15.210","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.176","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.143","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.94","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.36","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.0.13","lessThanOrEqual":"7.0.*","status":"unaffected","versionType":"semver"},{"version":"7.1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.9","versionEndExcluding":"5.15.210"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.9","versionEndExcluding":"6.1.176"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.9","versionEndExcluding":"6.6.143"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.9","versionEndExcluding":"6.12.94"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.9","versionEndExcluding":"6.18.36"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.9","versionEndExcluding":"7.0.13"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.9","versionEndExcluding":"7.1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/a3ee9231ccec6ec3be2de89c56f897055fd9eab1"},{"url":"https://git.kernel.org/stable/c/ec8e1e5842bc0dbd4c272761f4db3651eecd0339"},{"url":"https://git.kernel.org/stable/c/3b8b0c3631b19faee53f0d15a49924129b063eec"},{"url":"https://git.kernel.org/stable/c/994bd2b58d2bd08aa97ec0836cc813cfcb00d749"},{"url":"https://git.kernel.org/stable/c/910617a4e67dbdd5fdb39d9dc6a51e491e1b2c3e"},{"url":"https://git.kernel.org/stable/c/9545cc5ef18ca22d031f2f47c157192460652359"},{"url":"https://git.kernel.org/stable/c/f3c6aa078927e6fe8121c9c591ddee8716c5305a"}],"title":"net: mvpp2: limit XDP frame size to the RX buffer","x_generator":{"engine":"bippy-1.2.0"}}}}