Linux Kernel Vulnerability in skb_zerocopy Functionality, Impacting Open vSwitch
CVE-2026-90049

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
16 September 2026

What is CVE-2026-90049?

In the Linux kernel, a vulnerability exists within the skb_zerocopy function, which is designed to copy fragment data from one socket buffer (skb) to another. An issue arises during error handling operations when skb_tx_error is incorrectly applied to the source skb. This results in unintended modifications to the source skb, impacting its management within the network stack. The problem particularly affects Open vSwitch, where the error reporting and buffer management can lead to improper handling of fragmented packets and potential data leakage. Ensuring that error handling is properly isolated and the management of skb integrity is vital to maintaining network stability and security.

Affected Version(s)

Linux 36d5fe6a000790f56039afe26834265db0a3ad4c < 849bdb83123760a865bcb2970127f4c0b9423ba3

Linux 36d5fe6a000790f56039afe26834265db0a3ad4c

Linux 36d5fe6a000790f56039afe26834265db0a3ad4c < 767ec2a65cc022d303b0c9c12811e7db22057341

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.