CVE-2026-46320

In the Linux kernel, the following vulnerability has been resolved: tap: free page on error paths in tap_get_user_xdp() tap_get_user_xdp() rejects a frame shorter than ETH_HLEN with -EINVAL, and returns -ENOMEM when build_skb() fails. Both paths jump to the err label without freeing the page that vhost_net_build_xdp() allocated for the frame. tap_sendmsg() discards the per-buffer return value and always returns 0, so vhost_tx_batch() takes the success path and never frees the page; each rejected frame in a batch leaks one page-frag chunk. Free the page on both error paths, before the skb is built. This is the tap counterpart of the same leak in tun_xdp_one().
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc5:*:*:*:*:*:*

History

23 Jul 2026, 08:10

Type Values Removed Values Added
Summary
  • (es) En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta: tap: liberar página en las rutas de error en tap_get_user_xdp() tap_get_user_xdp() rechaza una trama más corta que ETH_HLEN con -EINVAL, y devuelve -ENOMEM cuando build_skb() falla. Ambas rutas saltan a la etiqueta err sin liberar la página que vhost_net_build_xdp() asignó para la trama. tap_sendmsg() descarta el valor de retorno por búfer y siempre devuelve 0, por lo que vhost_tx_batch() toma la ruta de éxito y nunca libera la página; cada trama rechazada en un lote filtra un fragmento de página. Liberar la página en ambas rutas de error, antes de que se construya el skb. Esta es la contraparte de tap de la misma fuga en tun_xdp_one().

08 Jul 2026, 16:27

Type Values Removed Values Added
CWE NVD-CWE-noinfo
First Time Linux linux Kernel
Linux
CPE cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc5:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:*
References () https://git.kernel.org/stable/c/18a84c35842e19cd3c5534d8cee73d31863f696d - () https://git.kernel.org/stable/c/18a84c35842e19cd3c5534d8cee73d31863f696d - Patch
References () https://git.kernel.org/stable/c/3bcf7aec6a9d16438f2cec29f5d7c8d5b8edf9b2 - () https://git.kernel.org/stable/c/3bcf7aec6a9d16438f2cec29f5d7c8d5b8edf9b2 - Patch
References () https://git.kernel.org/stable/c/3f52a86a482a69294c50a5a2a097bd6f4104990a - () https://git.kernel.org/stable/c/3f52a86a482a69294c50a5a2a097bd6f4104990a - Patch
References () https://git.kernel.org/stable/c/8d03e65eb6cfbffec471a6b65416f93679bf3286 - () https://git.kernel.org/stable/c/8d03e65eb6cfbffec471a6b65416f93679bf3286 - Patch
References () https://git.kernel.org/stable/c/d30aac0fa00ca0afc3e08174cf7f974a66bdcf05 - () https://git.kernel.org/stable/c/d30aac0fa00ca0afc3e08174cf7f974a66bdcf05 - Patch
References () https://git.kernel.org/stable/c/d68eab61944a9b0826fa2e954e42db1aa3201b7a - () https://git.kernel.org/stable/c/d68eab61944a9b0826fa2e954e42db1aa3201b7a - Patch
References () https://git.kernel.org/stable/c/e27c17346628cb56843a83f93ac63c314c00f388 - () https://git.kernel.org/stable/c/e27c17346628cb56843a83f93ac63c314c00f388 - Patch
References () https://git.kernel.org/stable/c/f979971835dddbca86cf99e3b2e2b94a408a1ab2 - () https://git.kernel.org/stable/c/f979971835dddbca86cf99e3b2e2b94a408a1ab2 - Patch

19 Jun 2026, 13:16

Type Values Removed Values Added
References
  • () https://git.kernel.org/stable/c/3f52a86a482a69294c50a5a2a097bd6f4104990a -
  • () https://git.kernel.org/stable/c/8d03e65eb6cfbffec471a6b65416f93679bf3286 -
  • () https://git.kernel.org/stable/c/d30aac0fa00ca0afc3e08174cf7f974a66bdcf05 -
  • () https://git.kernel.org/stable/c/d68eab61944a9b0826fa2e954e42db1aa3201b7a -
  • () https://git.kernel.org/stable/c/e27c17346628cb56843a83f93ac63c314c00f388 -
  • () https://git.kernel.org/stable/c/f979971835dddbca86cf99e3b2e2b94a408a1ab2 -

14 Jun 2026, 06:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.4

09 Jun 2026, 13:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-09 13:16

Updated : 2026-07-23 08:10


NVD link : CVE-2026-46320

Mitre link : CVE-2026-46320

CVE.ORG link : CVE-2026-46320


JSON object : View

Products Affected

linux

  • linux_kernel