CVE-2026-90115
CVE CVE-2026-90115EUVD EUVD-2026-81708Published 2026-09-17T16:06:21.000Z
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: xsk: fix NULL pointer dereference in __xsk_rcv() In the __xsk_rcv() multi-buffer path, xsk_buff_alloc() is called in a loop without checking its return value. xsk_buff_can_alloc() only counts fill queue entries without validating their addresses, so it can succeed while xsk_buff_alloc() rejects all remaining entries and returns NULL. Oops: general protection fault, probably for non-canonical address 0xdffffc0000000000 KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007] RIP: 0010:__xsk_rcv+0x426/0xc20 (net/xdp/xsk.c:350) Call Trace: xsk_generic_rcv+0x26d/0x5f0 xdp_do_generic_redirect+0x3c5/0xcf0 do_xdp_generic+0x92f/0xe70 __netif_receive_skb_core.constprop.0+0xf7e/0x2b30 Fix this with a two-stage transaction. First allocate and stage all buffers required for the packet, recycling all staged buffers with xsk_buff_free() if any allocation fails. Only after this stage succeeds, copy the data, reserve the RX descriptors, and release the buffers in an error-free loop.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux 6.6; patch: 6.6.157; patch: 6.12.110; 804627751b4281dd95148e7564759145da67855e <214fb79b0379cb0214905632a2537c0c33f594eb; 804627751b4281dd95148e7564759145da67855e <e37b2abca80473e106176e41712a369fd2f72117; patch: 0; 804627751b4281dd95148e7564759145da67855e <60d7d3559ce66e227e195e9463cdfed8077c8659; patch: 6.18.52; patch: 7.3-rc1; 804627751b4281dd95148e7564759145da67855e <8341bd3ff126d85bc8c4ed52eedcaa5b1a65f194; patch: 7.2.6; 804627751b4281dd95148e7564759145da67855e <aaebce297efc3e3dccb98a6ff838cfaa47db08db
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.