CVE-2026-81002

Source
https://cve.org/CVERecord?id=CVE-2026-81002
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-81002.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-81002
Downstream
Published
2026-09-11T19:42:55Z
Modified
2026-09-13T03:47:09Z
Summary
xdp: fix zero-copy frame layout
Details

In the Linux kernel, the following vulnerability has been resolved:

xdp: fix zero-copy frame layout

xdp_convert_zc_to_xdp_frame() clones an XSK packet into an order-0 page and advertises PAGE_SIZE as its frame size. It allows the copied frame to occupy the page tail needed by skb_shared_info and records zero headroom even when metadata separates the frame header from packet data. An AF_XDP zero-copy packet redirected through cpumap can therefore make the skb overlap skb_shared_info or place it beyond the allocated page.

Limit the copied layout to SKB_WITH_OVERHEAD(PAGE_SIZE) and include the metadata length in frame headroom. Redirect callers already handle a NULL conversion result.

BUG: KASAN: slab-out-of-bounds in skb_gro_receive Write of size 4 at addr ffff88800cf37004 by task cpumap/1/map:1/146 Call Trace: skb_gro_receive (net/core/gro.c:174) udp_gro_receive (net/ipv4/udp_offload.c:812) inet_gro_receive (net/ipv4/af_inet.c:1539) dev_gro_receive (net/core/gro.c:515) gro_receive_skb (net/core/gro.c:633) cpu_map_kthread_run (kernel/bpf/cpumap.c:395) kthread (kernel/kthread.c:436) ret_from_fork (arch/x86/kernel/process.c:164) ret_from_fork_asm (arch/x86/entry/entry_64.S:255) Kernel panic - not syncing: KASAN: panic_on_warn set ...

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/81xxx/CVE-2026-81002.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
b0d1beeff2a97a0cf1965ea8f1d13b8973f22582
Fixed
444216dacdbebd3e52d5e704facafbb230da09e9
Fixed
15d1f3c0dbe7a740f779337deb39f23cd8d002c8
Fixed
68d7cc5512238693670fc19c7a615df631e10edf
Fixed
71283aaa6c65b3cec84caf1dc78560985737641f

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-81002.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.20.0
Fixed
6.12.109
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.50
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-81002.json"