Linux Kernel Vulnerability Impacting Managed Frags in ESP Functionality
CVE-2026-98368
What is CVE-2026-98368?
In the Linux kernel, a vulnerability has been identified with the ESP functionality, specifically related to the management of zerocopy fragments. When handling out-of-place output paths (where esp->inplace is false), the ESP process mutates the skb frag array incorrectly by appending and replacing frags without properly downgrading the skb. This mishandling can lead to a use-after-free scenario, impacting managed-frag invariants and causing potential memory leaks. The issue arises as esp_ssg_unref() improperly drops references on ubuf-owned payload frags, while esp_output_tail() adds destination pages without clearing relevant flags, leading to instability and vulnerabilities that can be exploited in packet processing.
Affected Version(s)
Linux 753f1ca4e1e50248a1b760c9774d6d6b354562cc < 2359264f377cdbdef2d95868cc8fb572949e48d3
Linux 753f1ca4e1e50248a1b760c9774d6d6b354562cc < 69a768c12398cada8528080332c822623fa7064d
Linux 753f1ca4e1e50248a1b760c9774d6d6b354562cc < 6508304ac2c8cdafca2f4ab915df8c707893e134