Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerability · NVD

CVE-2026-46300

CVE-2026-46300 : high severity (CVSS 7.8). No tracked catalog app is linked to this CVE.

Severity (CVSS)
7.8

NVD scale

Exploitation
9.5 %

EPSS, predicted over 30 days

Tracked apps
0
Still exposed
0
Public exploit : ExploitDB

In the Linux kernel, the following vulnerability has been resolved:

net: skbuff: preserve shared-frag marker during coalescing

skb_try_coalesce() can attach paged frags from @from to @to. If @from
has SKBFL_SHARED_FRAG set, the resulting @to skb can contain the same
externally-owned or page-cache-backed frags, but the shared-frag marker
is currently lost.

That breaks the invariant relied on by later in-place writers. In
particular, ESP input checks skb_has_shared_frag() before deciding
whether an uncloned nonlinear skb can skip skb_cow_data(). If TCP
receive coalescing has moved shared frags into an unmarked skb, ESP can
see skb_has_shared_frag() as false and decrypt in place over page-cache
backed frags.

Propagate SKBFL_SHARED_FRAG when skb_try_coalesce() transfers paged
frags. The tailroom copy path does not need the marker because it copies
bytes into @to's linear data rather than transferring frag descriptors.

Attack vector : Local No user interaction
Show raw CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS 9.48% above median percentile 95.1%
View on NVD ↗ Advisory · git.kernel.org