CVE-2026-46321

In the Linux kernel, the following vulnerability has been resolved: tun: free page on short-frame rejection in tun_xdp_one() tun_xdp_one() returns -EINVAL on a frame shorter than ETH_HLEN without freeing the page that vhost_net_build_xdp() allocated for it. tun_sendmsg() discards that -EINVAL and still returns total_len, so vhost_tx_batch() takes the success path and never frees the page; each short frame in a batch leaks one page-frag chunk. A local process that can open /dev/net/tun and /dev/vhost-net can hit this path: it attaches a tun/tap device as the vhost-net backend and feeds TX descriptors whose length minus the virtio-net header is below ETH_HLEN. Each kick leaks the page-frag chunks for that batch, and a tight submission loop exhausts host memory and triggers an OOM panic. Free the page before returning -EINVAL, matching the XDP-program error path in the same function.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc5:*:*:*:*:*:*

History

23 Jul 2026, 08:10

Type Values Removed Values Added
Summary
  • (es) En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta: tun: liberar página en el rechazo de tramas cortas en tun_xdp_one() tun_xdp_one() devuelve -EINVAL en una trama más corta que ETH_HLEN sin liberar la página que vhost_net_build_xdp() asignó para ella. tun_sendmsg() descarta ese -EINVAL y aún devuelve total_len, por lo que vhost_tx_batch() toma la ruta de éxito y nunca libera la página; cada trama corta en un lote filtra un chunk de fragmento de página. Un proceso local que puede abrir /dev/net/tun y /dev/vhost-net puede alcanzar esta ruta: adjunta un dispositivo tun/tap como el backend de vhost-net y alimenta descriptores TX cuya longitud menos el encabezado virtio-net está por debajo de ETH_HLEN. Cada kick filtra los chunks de fragmentos de página para ese lote, y un bucle de envío ajustado agota la memoria del host y desencadena un pánico OOM. Liberar la página antes de devolver -EINVAL, coincidiendo con la ruta de error del programa XDP en la misma función.

08 Jul 2026, 16:23

Type Values Removed Values Added
First Time Linux linux Kernel
Linux
CPE cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc5:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:*
CWE NVD-CWE-noinfo
References () https://git.kernel.org/stable/c/0a6f46a9332ad6958992d64d3b3a81a80b2ca940 - () https://git.kernel.org/stable/c/0a6f46a9332ad6958992d64d3b3a81a80b2ca940 - Patch
References () https://git.kernel.org/stable/c/0e8211fcf9426f5adddf32516ba0f400ceb9544d - () https://git.kernel.org/stable/c/0e8211fcf9426f5adddf32516ba0f400ceb9544d - Patch
References () https://git.kernel.org/stable/c/37a1c268c2c8090bf4dc552d732bd23ba36f8eb0 - () https://git.kernel.org/stable/c/37a1c268c2c8090bf4dc552d732bd23ba36f8eb0 - Patch
References () https://git.kernel.org/stable/c/5b34f9e4fe2f203724a6e893d6df0316b9670057 - () https://git.kernel.org/stable/c/5b34f9e4fe2f203724a6e893d6df0316b9670057 - Patch
References () https://git.kernel.org/stable/c/69863ff2720a0e9871f1a5710f2a33a94217fee0 - () https://git.kernel.org/stable/c/69863ff2720a0e9871f1a5710f2a33a94217fee0 - Patch
References () https://git.kernel.org/stable/c/98c67be9eb9de72465a071949e84a3cdb8fab5a3 - () https://git.kernel.org/stable/c/98c67be9eb9de72465a071949e84a3cdb8fab5a3 - Patch
References () https://git.kernel.org/stable/c/e915445942af6dcea628bf66d6241641201a0c41 - () https://git.kernel.org/stable/c/e915445942af6dcea628bf66d6241641201a0c41 - Patch
References () https://git.kernel.org/stable/c/f4feb1e20058e407cb00f45aff47f5b7e19a6bbf - () https://git.kernel.org/stable/c/f4feb1e20058e407cb00f45aff47f5b7e19a6bbf - Patch

19 Jun 2026, 13:16

Type Values Removed Values Added
References
  • () https://git.kernel.org/stable/c/0a6f46a9332ad6958992d64d3b3a81a80b2ca940 -
  • () https://git.kernel.org/stable/c/0e8211fcf9426f5adddf32516ba0f400ceb9544d -
  • () https://git.kernel.org/stable/c/5b34f9e4fe2f203724a6e893d6df0316b9670057 -
  • () https://git.kernel.org/stable/c/e915445942af6dcea628bf66d6241641201a0c41 -

14 Jun 2026, 06:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.1

09 Jun 2026, 13:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-09 13:16

Updated : 2026-07-23 08:10


NVD link : CVE-2026-46321

Mitre link : CVE-2026-46321

CVE.ORG link : CVE-2026-46321


JSON object : View

Products Affected

linux

  • linux_kernel