KernelScan.io

CRITICAL Introduced in 4.20

xdp ZcFrame OOB

CVE-2026-81002

CVSS 9.8 / 10.0 NVD

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

KernelScan AI6.7MEDIUM

01

In the Linux kernel, the following vulnerability has been resolved: xdp: fix zero-copy frame layout xdp_convert_zc_to_xdp_frame() clones an XSK packet into an order-0 page and advertises PAGE_SIZE as its frame size. It allows the copied frame to occupy the page tail needed by skb_shared_info and records zero headroom even when metadata separates the frame header from packet data. An AF_XDP zero-copy packet redirected through cpumap can therefore make the skb overlap skb_shared_info or place it beyond the allocated page. Limit the copied layout to SKB_WITH_OVERHEAD(PAGE_SIZE) and include the metadata length in frame headroom. Redirect callers already handle a NULL conversion result. BUG: KASAN: slab-out-of-bounds in skb_gro_receive Write of size 4 at addr ffff88800cf37004 by task cpumap/1/map:1/146 Call Trace: skb_gro_receive (net/core/gro.c:174) udp_gro_receive (net/ipv4/udp_offload.c:812) inet_gro_receive (net/ipv4/af_inet.c:1539) dev_gro_receive (net/core/gro.c:515) gro_receive_skb (net/core/gro.c:633) cpu_map_kthread_run (kernel/bpf/cpumap.c:395) kthread (kernel/kthread.c:436) ret_from_fork (arch/x86/kernel/process.c:164) ret_from_fork_asm (arch/x86/entry/entry_64.S:255) Kernel panic - not syncing: KASAN: panic_on_warn set ...

02

Engine v0.6.0

Risk summary

A local attacker with network administration privileges can trigger an out-of-bounds write in the kernel heap by sending a crafted AF_XDP zero-copy packet redirected through a cpumap. The corruption can lead to kernel memory read/write primitives, data corruption, or a kernel panic, affecting system confidentiality, integrity, and availability.

Affectednet/core/xdp.c (XDP subsystem)

Vulnerability analysis

When an AF_XDP zero-copy packet is redirected through a cpumap, the code that copies the packet into a fresh page incorrectly treats the entire page as usable packet space, failing to reserve the trailing area that the kernel later uses for its own bookkeeping. It also fails to leave space before the packet when metadata sits between the buffer start and the actual data. This allows the packet data to spill into the reserved trailing area or past the end of the page, so when the receiving path later writes its bookkeeping data it does so out of bounds. The fix reduces the usable layout to leave room for that trailing overhead and correctly accounts for any metadata length as leading space; redirect paths already tolerate a failed copy. Triggering this requires local access with the ability to create AF_XDP zero-copy sockets and attach an XDP redirect program to a network interface that supports zero-copy, which demands CAP_NET_ADMIN in the init namespace.

03

BranchIntroducedFixed inPatch commit
5.154.205.15.221220927301290
6.14.206.1.188ced3e18cd9b9
6.64.206.6.1576de17275b3cc
6.124.206.12.109444216dacdbe
6.184.206.18.5015d1f3c0dbe7
7.24.207.2.468d7cc551223
mainline4.207.3-rc171283aaa6c65
5.104.205.10.270dcb6db9ca651