KernelScan.io

HIGH Introduced in 6.0

net/gro ZCopy UAF

CVE-2026-46323

CVSS 7.8 / 10.0 NVD

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

KernelScan AI7.8HIGH

01

In the Linux kernel, the following vulnerability has been resolved: net: gro: don't merge zcopy skbs skb_gro_receive() can currently copy frags between the source and GRO skb, without checking the zerocopy status, and in particular the SKBFL_MANAGED_FRAG_REFS flag. When SKBFL_MANAGED_FRAG_REFS is set, the skb doesn't hold a reference on the pages in shinfo->frags. Appending those frags to another skb's frags without fixing up the page refcount can lead to UAF. When either the last skb in the GRO chain (the one we would append frags to) or the source skb is zerocopy, don't merge the skbs.

02

Engine v0.2.0

Risk summary

Local attackers with low privileges can trigger a use-after-free in the kernel's Generic Receive Offload (GRO) code by exploiting improper handling of zero-copy socket buffers (e.g., via io_uring or zerocopy socket options). This can lead to arbitrary code execution, privilege escalation, or system crashes on systems with GRO enabled.

Affectednet/core/gro.c (networking GRO)

Vulnerability analysis

The vulnerability occurs in skb_gro_receive() which merges socket buffers during Generic Receive Offload processing. When SKBFL_MANAGED_FRAG_REFS is set on zero-copy skbs, the kernel doesn't hold references to pages in the fragment list, but the GRO code was copying fragments between skbs without checking this flag or fixing up page reference counts. This creates a use-after-free condition when pages are freed while still referenced by merged skbs. The fix prevents merging of any zero-copy skbs by returning -ETOOMANYREFS when either source or destination skb has zero-copy flags set. The trigger requires local socket operations that produce zero-copy buffers and cause them to be processed by GRO; remote network packets do not carry the zero-copy flag required to reach the buggy path.

03

BranchIntroducedFixed inPatch commit
6.16.06.1.1763c6cc9f2ca65
6.126.06.12.92479084ae0e1d
7.06.07.0.1144bea2032af0
mainline6.07.14db79a322db8
6.66.06.6.1421f9c82855641
6.186.06.18.34e334cbf3388f