{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-80977","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-08-26T14:34:25.811Z","datePublished":"2026-09-11T19:42:38.862Z","dateUpdated":"2026-09-14T11:59:22.460Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-14T11:59:22.460Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: skbuff: don't touch shared zerocopy state in skb_tx_error()\n\nskb_tx_error() completes the zerocopy uarg and clears\nSKBFL_ALL_ZEROCOPY, and skb_zcopy_downgrade_managed() clears\nSKBFL_MANAGED_FRAG_REFS. Both live in skb_shinfo(), which every clone\nshares, while the caller only owns the reference it is about to drop.\nThrough a clone it tells the producer its pages are free and drops\nSKBFL_SHARED_FRAG for an skb that is still in flight.\n\nOpen vSwitch reaches this with a non-last OVS_ACTION_ATTR_RECIRC:\nclone_execute() sends a skb_clone() into ovs_dp_process_packet() while\ndo_execute_actions() keeps forwarding the original, and skb_clone()\ndoes not privatise the frags here -- skb_orphan_frags() returns early\non SKBFL_DONT_ORPHAN. A flow miss on the clone then strips the marker\nfrom the packet still being forwarded, and a later local ESP delivery\ndecrypts in place over frags it does not own privately.\n\nSkip it for a cloned skb. Nothing is lost: skb_release_data() clears\nthe zerocopy state once the last reference to the shared data goes."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The buggy state is a locally originated MSG_ZEROCOPY/io_uring TX skb (SKBFL_DONT_ORPHAN plus a uarg); NIC-received packets never carry that marker, and the skb must still be forwarded into local ESP, so a local account is required.\nAC:L - The attacker fully controls both sides: OVS flows with a non-last RECIRC, a guaranteed miss/upcall failure on the clone, MSG_ZEROCOPY send, and the ESP SA/payload, so the shared-shinfo strip and in-place decrypt are reliably reproducible with no race beyond attacker influence.\nPR:L - An unprivileged user can enable SO_ZEROCOPY and, via unshare -Urn, obtain CAP_NET_ADMIN in a user+net namespace; OVS genetlink uses GENL_UNS_ADMIN_PERM and XFRM SAs are likewise namespace-installable, while the global page cache remains the corruption target.\nUI:N - The attacker installs the OVS recirc flow, sends the MSG_ZEROCOPY packet, and completes local ESP delivery without any victim action.\nS:U - The resulting page-cache write and premature zerocopy completion stay inside the host kernel's memory authority as a standard local memory-corruption/LPE primitive and do not cross a VM or IOMMU boundary.\nC:H - skb_tx_error() on the clone completes the shared uarg and clears SKBFL_SHARED_FRAG, so later in-place ESP decrypt (and UAF of still-mapped pages) corrupts globally cached file/code pages and can be leveraged for arbitrary disclosure.\nI:H - With the shared-frag marker stripped, esp_input() skips skb_cow_data() and AEAD-decrypts attacker-controlled plaintext in place over page-cache-backed frags, yielding an unprivileged write into files the sender could only read (the Fragnesia primitive).\nA:H - Use-after-free of zerocopy pages still referenced by the in-flight original skb, plus overwriting page-cache-backed executable or kernel-managed data, causes oopses, panics, and process crashes."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/core/skbuff.c"],"versions":[{"version":"25121173f7b1e4ac3fc692df6e7b8c52ec36abba","lessThan":"6493165034bca14033bf49c9cec7b45e97a91497","status":"affected","versionType":"git"},{"version":"25121173f7b1e4ac3fc692df6e7b8c52ec36abba","lessThan":"b4452349dcf4d561e13be768d5d278de58248930","status":"affected","versionType":"git"},{"version":"25121173f7b1e4ac3fc692df6e7b8c52ec36abba","lessThan":"363c4252ffc473a0203e91b83ede5519dfb8bd07","status":"affected","versionType":"git"},{"version":"25121173f7b1e4ac3fc692df6e7b8c52ec36abba","lessThan":"6ec22afc82a3cae07ade0a6ec361ae2532128ff5","status":"affected","versionType":"git"},{"version":"25121173f7b1e4ac3fc692df6e7b8c52ec36abba","lessThan":"15aa81b390d401abf4b8211042470e9e92e3b7fb","status":"affected","versionType":"git"},{"version":"25121173f7b1e4ac3fc692df6e7b8c52ec36abba","lessThan":"288f9970670841044ab030104fa6b6ed159949d0","status":"affected","versionType":"git"},{"version":"25121173f7b1e4ac3fc692df6e7b8c52ec36abba","lessThan":"0370da114a9bc044e248b85c6809d1b5e0c1f7f9","status":"affected","versionType":"git"},{"version":"25121173f7b1e4ac3fc692df6e7b8c52ec36abba","lessThan":"f66bdb1cc0fcd227a062378f8be0b5873aa5600a","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/core/skbuff.c"],"versions":[{"version":"3.8","status":"affected"},{"version":"0","lessThan":"3.8","status":"unaffected","versionType":"semver"},{"version":"5.10.270","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.221","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.188","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.109","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.50","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.8","versionEndExcluding":"5.10.270"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.8","versionEndExcluding":"5.15.221"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.8","versionEndExcluding":"6.1.188"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.8","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.8","versionEndExcluding":"6.12.109"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.8","versionEndExcluding":"6.18.50"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.8","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.8","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/6493165034bca14033bf49c9cec7b45e97a91497"},{"url":"https://git.kernel.org/stable/c/b4452349dcf4d561e13be768d5d278de58248930"},{"url":"https://git.kernel.org/stable/c/363c4252ffc473a0203e91b83ede5519dfb8bd07"},{"url":"https://git.kernel.org/stable/c/6ec22afc82a3cae07ade0a6ec361ae2532128ff5"},{"url":"https://git.kernel.org/stable/c/15aa81b390d401abf4b8211042470e9e92e3b7fb"},{"url":"https://git.kernel.org/stable/c/288f9970670841044ab030104fa6b6ed159949d0"},{"url":"https://git.kernel.org/stable/c/0370da114a9bc044e248b85c6809d1b5e0c1f7f9"},{"url":"https://git.kernel.org/stable/c/f66bdb1cc0fcd227a062378f8be0b5873aa5600a"}],"title":"net: skbuff: don't touch shared zerocopy state in skb_tx_error()","x_generator":{"engine":"bippy-1.2.0"}}}}