{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-90086","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.785Z","datePublished":"2026-09-17T16:06:02.212Z","dateUpdated":"2026-09-17T16:06:02.212Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-17T16:06:02.212Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nxsk: honor XDP_TX_METADATA in zero-copy path\n\nThe zero-copy path reads TX metadata whenever the UMEM has metadata space,\neven if the descriptor does not set XDP_TX_METADATA. Pass descriptor\noptions through the metadata helpers and ignore metadata unless the option\nis set.\n\nThis does not fix the existing per-WQE metadata handling for mlx5 MPWQEs.\nOnly the descriptor that starts a session passes through\nxsk_tx_metadata_request() and configures offload state shared by the batch.\nMetadata on descriptors joining an open session is therefore not validated\nand does not configure its requested offloads. In addition, a non-NULL\nmetadata pointer from such a descriptor is treated as a timestamp\ncompletion request even when XDP_TXMD_FLAGS_TIMESTAMP is not set, so its\nmetadata union can be overwritten with an unrequested timestamp. Fixing\nmixed metadata states within one MPWQE requires a separate change."}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/net/ethernet/intel/igc/igc_main.c","drivers/net/ethernet/mellanox/mlx5/core/en/xsk/tx.c","drivers/net/ethernet/stmicro/stmmac/stmmac_main.c","include/net/libeth/xsk.h","include/net/xdp_sock_drv.h","include/net/xsk_buff_pool.h","net/xdp/xsk_buff_pool.c"],"versions":[{"version":"48eb03dd26304c24f03bdbb9382e89c8564e71df","lessThan":"53a5b262d706b572840cbe8feae392538077ee19","status":"affected","versionType":"git"},{"version":"48eb03dd26304c24f03bdbb9382e89c8564e71df","lessThan":"bf9387488d6394845076928c6ca5315ce5d84f54","status":"affected","versionType":"git"},{"version":"48eb03dd26304c24f03bdbb9382e89c8564e71df","lessThan":"a6e4b9a6deb9362ef7a0706c70d674e92fe1411a","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/net/ethernet/intel/igc/igc_main.c","drivers/net/ethernet/mellanox/mlx5/core/en/xsk/tx.c","drivers/net/ethernet/stmicro/stmmac/stmmac_main.c","include/net/libeth/xsk.h","include/net/xdp_sock_drv.h","include/net/xsk_buff_pool.h","net/xdp/xsk_buff_pool.c"],"versions":[{"version":"6.8","status":"affected"},{"version":"0","lessThan":"6.8","status":"unaffected","versionType":"semver"},{"version":"6.18.52","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.6","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.8","versionEndExcluding":"6.18.52"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.8","versionEndExcluding":"7.2.6"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.8","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/53a5b262d706b572840cbe8feae392538077ee19"},{"url":"https://git.kernel.org/stable/c/bf9387488d6394845076928c6ca5315ce5d84f54"},{"url":"https://git.kernel.org/stable/c/a6e4b9a6deb9362ef7a0706c70d674e92fe1411a"}],"title":"xsk: honor XDP_TX_METADATA in zero-copy path","x_generator":{"engine":"bippy-1.2.0"}}}}