CVE-2026-89487
CVE CVE-2026-89487EUVD EUVD-2026-76393Veröffentlicht 2026-09-11T19:43:40.000ZZuletzt geändert 2026-09-14T12:00:22.000ZCVSS 7.8
Was das Advisory beschreibt
In the Linux kernel, the following vulnerability has been resolved: openvswitch: only skb_tx_error() a packet we are about to drop queue_userspace_packet() borrows the packet skb -- it only copies it into a private netlink message (user_skb) and does not own it; on return do_execute_actions() keeps forwarding it through the flow's remaining actions. Its error path nevertheless calls skb_tx_error(skb), which via skb_zcopy_clear() does skb_shinfo(skb)->flags &= ~SKBFL_ALL_ZEROCOPY, stripping SKBFL_SHARED_FRAG from that live skb (skb_tx_error()'s kerneldoc says "skb must be freed afterwards"). For a MSG_ZEROCOPY skb carrying page-cache frags, SKBFL_SHARED_FRAG is what makes esp_input() skb_cow_data() before in-place AEAD; once it is stripped a later local ESP-in-UDP delivery decrypts in place over pages the sender does not own -- an unprivileged page-cache write (the "Fragnesia" primitive). do_execute_actions() ignores output_userspace()'s return value, so any action after a failed USERSPACE upcall inherits the stripped skb. Move the skb_tx_error() to the flow-miss drop path - the "default" branch of ovs_dp_process_packet()'s switch(error), before kfree_skb(). The call has been here since commit 36d5fe6a0007 ("core, nfqueue, openvswitch: Orphan frags in skb_zerocopy and handle errors") but was harmless until esp_input() began relying on SKBFL_SHARED_FRAG to gate in-place decrypt; only then did stripping it on a still-forwarded skb become a page-cache write primitive.
Quelle: EUVD (ENISA), im Wortlaut der Meldung.
Produkte, die das Advisory nennt
Diese Angaben stammen aus der Meldung selbst, nicht aus einer Prüfung durch uns.
- Linux — Linux 36d5fe6a000790f56039afe26834265db0a3ad4c <48db11e115d1b232edc5591604adc6eda95cd545; patch: 6.1.188; patch: 6.18.50; 36d5fe6a000790f56039afe26834265db0a3ad4c <4d5c460ef8754be1d43b16dbf02695b008b207d6; patch: 7.3-rc1; 36d5fe6a000790f56039afe26834265db0a3ad4c <e41a59fc056f63a7a1f42788913c53cc48d744aa; patch: 6.12.109; 36d5fe6a000790f56039afe26834265db0a3ad4c <0dbc2398fca3bb33eda963849f865ddb1b3aa05e; patch: 0; patch: 5.10.270; patch: 6.6.157; 36d5fe6a000790f56039afe26834265db0a3ad4c <6767d70cf46f65807a6a4c4406a518e6c12e36ae; patch: 5.15.221; 36d5fe6a000790f56039afe26834265db0a3ad4c <5d85eef222cfd28e73deed7402c100229e8b9e6e; 3.14; 36d5fe6a000790f56039afe26834265db0a3ad4c <4477222e2916a18e273edc139c955ade6bbb7a69; c5f0c0e7525443add533495e93ba8de6feab2396; patch: 7.2.4; 3.12.40 <3.13; 36d5fe6a000790f56039afe26834265db0a3ad4c <5de5d554141a15b3f1f5c978fd9f7f4fd6d0600a; 1674b4bf3eea3cac51b70778e89f8025f7cfe695; 3.10.51 <3.11
Die genannten Versionen sind die Angabe der Meldung. Patchlage vergleicht keine Versionsnummern und leitet aus ihnen keine Aussage ab — welche Version installiert ist, muss ein Mensch nachsehen.
Im Produktkatalog geführt
Für diese Produkte kann ein Bestand in Patchlage erfasst werden. Ein Advisory dazu erscheint am Morgen danach im Lagebericht.
- Linux — Linux
Betrifft das einen Ihrer Kundenbestände?
Diese Seite kann die Frage nicht beantworten — sie kennt Ihren Bestand nicht. Wer seine Umgebungen erfasst hat, bekommt die Antwort am Morgen nach der Veröffentlichung, zusammen mit einem Absatz, den er unverändert an den Kunden weitergeben kann.
28 Tage testenPatchlage meldet Treffer und Verdachtsfälle. Zu allem anderen sagt dieses System nichts — weder diese Seite noch der Lagebericht behauptet je, dass ein Bestand sicher ist.