CVE-2026-90115

Source
https://cve.org/CVERecord?id=CVE-2026-90115
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90115.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-90115
Downstream
Published
2026-09-17T16:06:21Z
Modified
2026-09-18T03:48:35Z
Summary
xsk: fix NULL pointer dereference in __xsk_rcv()
Details

In the Linux kernel, the following vulnerability has been resolved:

xsk: fix NULL pointer dereference in __xsk_rcv()

In the __xsk_rcv() multi-buffer path, xsk_buff_alloc() is called in a loop without checking its return value. xsk_buff_can_alloc() only counts fill queue entries without validating their addresses, so it can succeed while xsk_buff_alloc() rejects all remaining entries and returns NULL.

Oops: general protection fault, probably for non-canonical address 0xdffffc0000000000 KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007] RIP: 0010:__xsk_rcv+0x426/0xc20 (net/xdp/xsk.c:350) Call Trace: xsk_generic_rcv+0x26d/0x5f0 xdp_do_generic_redirect+0x3c5/0xcf0 do_xdp_generic+0x92f/0xe70 __netif_receive_skb_core.constprop.0+0xf7e/0x2b30

Fix this with a two-stage transaction. First allocate and stage all buffers required for the packet, recycling all staged buffers with xsk_buff_free() if any allocation fails. Only after this stage succeeds, copy the data, reserve the RX descriptors, and release the buffers in an error-free loop.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/90xxx/CVE-2026-90115.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
804627751b4281dd95148e7564759145da67855e
Fixed
aaebce297efc3e3dccb98a6ff838cfaa47db08db
Fixed
60d7d3559ce66e227e195e9463cdfed8077c8659
Fixed
214fb79b0379cb0214905632a2537c0c33f594eb
Fixed
8341bd3ff126d85bc8c4ed52eedcaa5b1a65f194
Fixed
e37b2abca80473e106176e41712a369fd2f72117

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90115.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.6.0
Fixed
6.6.157
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.110
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.52
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90115.json"