CVE-2026-90051
CVE CVE-2026-90051EUVD EUVD-2026-81912Published 2026-09-17T16:05:37.000ZLast changed 2026-09-18T17:52:45.000ZCVSS 7.8
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: tcp: reject non zerocopy devmem tx Devmem tcp tx doesn't work without zero-copy, however it's not currently enforced if NETIF_F_SG isn't present. In this case, tcp_sendmsg_locked() will try the copy path and try to copy data from an iovec which consists of offsets into the dma-buf and would normally fail. Moreover, d9c56501c72fd ("net: tcp: block mixing readable and unreadable frags") relies on that and assumes that the devmem binding is present IFF we're using the zero-copy path, which can be used to mix net-iov and pages in a single skb, and break invariants. Let's reject devmem tx without zero-copy. Note, the parameter check the patch is modifying is too loose, we can create an io_uring request with dmabuf_id and all ZC flags, but which won't have the binding. We replace it with stricter validation.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux bd61848900bff597764238f3a8ec67c815cd316e <2151b2bcf6fcec52665f606eed20da068447f0b7; patch: 0; patch: 7.2.6; patch: 7.3-rc3; 6.16; bd61848900bff597764238f3a8ec67c815cd316e <125755776bc6d4dd53eaf551c87e3d460625d638; bd61848900bff597764238f3a8ec67c815cd316e <b04326c7927af7048fd4e730f5770cca350d0a60; patch: 6.18.52
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.