In the Linux kernel, the following vulnerability has been resolved:
xfrm: iptfs: propagate SKBFLSHAREDFRAG in iptfsskbadd_frags()
When iptfsskbadd_frags() copies frag references from the source frag walk into a new SKB, it increments the page reference count via _skbfragref() but does not propagate SKBFLSHAREDFRAG to the destination SKB's skbshinfo->flags.
If the source SKB carries shared frags (e.g. from a page-pool backed receive path), the new inner SKB will appear to ESP as having privately owned frags. A subsequent esp_input() call for a nested transport-mode SA then takes the no-COW fast path and decrypts in place, writing over pages that are still referenced by the outer IPTFS SKB. This causes kernel-visible memory corruption and can trigger a panic.
All other frag-transfer helpers in the kernel (skbtrycoalesce, skbgroreceive, __pskbcopyfclone, skb_shift, skbsegment) correctly propagate SKBFLSHAREDFRAG; align iptfsskbaddfrags() with this convention by setting the flag inside the loop immediately after _skbfragref() and nrfrags++, so every exit path that attaches a frag unconditionally propagates SKBFLSHAREDFRAG.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64566.json",
"cna_assigner": "Linux"
}