CVE-2026-46323
Vulnerability Summary
Timeline
Description
In the Linux kernel, the following vulnerability has been resolved: net: gro: don't merge zcopy skbs skb_gro_receive() can currently copy frags between the source and GRO skb, without checking the zerocopy status, and in particular the SKBFL_MANAGED_FRAG_REFS flag. When SKBFL_MANAGED_FRAG_REFS is set, the skb doesn't hold a reference on the pages in shinfo->frags. Appending those frags to another skb's frags without fixing up the page refcount can lead to UAF. When either the last skb in the GRO chain (the one we would append frags to) or the source skb is zerocopy, don't merge the skbs.
CVSS Metrics
- v4.0•HIGH•Score: 7.3CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- v3.1•HIGH•Score: 7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Trends
Current EPSS score: 0.14%• Percentile: 3%
Techniques & Countermeasures
- CWE-416•Use After Free
The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.
- CWE-123•Write-what-where Condition
Any condition where the attacker has the ability to write an arbitrary value to an arbitrary location, often as the result of a buffer overflow.
Affected Systems
- debian•linux
< 6.1.176-1 | < 6.12.94-1 | < 7.0.12-1
- debian•linux-6.1
< 6.1.176-1~deb11u1
- ubuntu•linux
< 6.8.0-124.124 | < 6.17.0-35.35 | < 7.0.0-22.22
- ubuntu•linux-allwinner-5.19
all
- ubuntu•linux-aws
< 6.8.0-1057.60 | < 6.17.0-1017.17 | < 7.0.0-1006.6
- ubuntu•linux-aws-5.0
all
- ubuntu•linux-aws-5.11
all
- ubuntu•linux-aws-5.13
all
- ubuntu•linux-aws-5.19
all
- ubuntu•linux-aws-5.3
all
- ubuntu•linux-aws-5.8
all
- ubuntu•linux-aws-6.14
all
- ubuntu•linux-aws-6.17
< 6.17.0-1017.17~24.04.1
- ubuntu•linux-aws-6.2
all
- ubuntu•linux-aws-6.5
all
- ubuntu•linux-aws-6.8
< 6.8.0-1057.60~22.04.1
- ubuntu•linux-aws-fips
< 6.8.0-1057.60+fips1
- ubuntu•linux-azure
all | < 6.8.0-1058.64 | < 6.17.0-1017.17 | < 7.0.0-1007.7
- ubuntu•linux-azure-5.11
all
- ubuntu•linux-azure-5.13
all
- ubuntu•linux-azure-5.19
all
- ubuntu•linux-azure-5.3
all
- ubuntu•linux-azure-5.8
all
- ubuntu•linux-azure-6.11
all
- ubuntu•linux-azure-6.14
all
- ubuntu•linux-azure-6.17
< 6.17.0-1017.17~24.04.1
- ubuntu•linux-azure-6.2
all
- ubuntu•linux-azure-6.5
all
- ubuntu•linux-azure-6.8
< 6.8.0-1059.65~22.04.1
- ubuntu•linux-azure-edge
all
- ubuntu•linux-azure-fde
all | all | all | all
- ubuntu•linux-azure-fde-5.19
all
- ubuntu•linux-azure-fde-6.14
all
- ubuntu•linux-azure-fde-6.2
all
- ubuntu•linux-azure-fde-6.8
all
- ubuntu•linux-azure-fde-7.0
all
- ubuntu•linux-azure-fips
< 6.8.0-1059.65+fips1
- ubuntu•linux-azure-nvidia
all
- ubuntu•linux-azure-nvidia-6.14
all
- ubuntu•linux-bluefield
all | < 6.8.0-1023.27
- ubuntu•linux-fips
< 6.8.0-124.124+fips1
- ubuntu•linux-gcp
all | < 6.8.0-1060.63 | < 6.17.0-1018.19 | < 7.0.0-1005.5
- ubuntu•linux-gcp-5.11
all
- ubuntu•linux-gcp-5.13
all
- ubuntu•linux-gcp-5.19
all
- ubuntu•linux-gcp-5.3
all
- ubuntu•linux-gcp-5.8
all
- ubuntu•linux-gcp-6.11
all
- ubuntu•linux-gcp-6.14
all
- ubuntu•linux-gcp-6.17
< 6.17.0-1018.19~24.04.1
Showing first 50 affected entries in server-rendered view.
References (44)
- https://git.kernel.org/stable/c/1f9c828556416fbe3f49386708ce999fc4d4da06
- https://git.kernel.org/stable/c/479084ae0e1d9cb7929cb4298d35623de189f80a
- https://git.kernel.org/stable/c/e334cbf3388fd9334503a778a82d9e9f14dd2f71
- https://git.kernel.org/stable/c/44bea2032af0425e4ce6d26a8af0ede79db49ec1
- https://git.kernel.org/stable/c/4db79a322db8c97f7b73b8a347395ef4d685eb40
- https://git.kernel.org/stable/c/3c6cc9f2ca65b6dd61b1af75452dc0e1cd0aad8d
- https://access.redhat.com/security/cve/CVE-2026-46323
- https://bugzilla.redhat.com/show_bug.cgi?id=2479832
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-46323.json
- https://access.redhat.com/errata/RHSA-2026:27731
- https://access.redhat.com/errata/RHSA-2026:27735
- https://access.redhat.com/errata/RHSA-2026:27708
- https://access.redhat.com/errata/RHSA-2026:36018
- https://access.redhat.com/errata/RHSA-2026:47727
- https://access.redhat.com/errata/RHSA-2026:44230
- https://access.redhat.com/errata/RHSA-2026:44231
- https://access.redhat.com/errata/RHSA-2026:44259
- https://access.redhat.com/errata/RHSA-2026:44262
- https://access.redhat.com/errata/RHSA-2026:44270
- https://access.redhat.com/security/updates/classification/#important
- https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_44270.json
- https://www.cve.org/CVERecord?id=CVE-2026-46323
- https://nvd.nist.gov/vuln/detail/CVE-2026-46323
- https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=1f9c828556416fbe3f49386708ce999fc4d4da06
- https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=44bea2032af0425e4ce6d26a8af0ede79db49ec1
- https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=479084ae0e1d9cb7929cb4298d35623de189f80a
- https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=4db79a322db8c97f7b73b8a347395ef4d685eb40
- https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=e334cbf3388fd9334503a778a82d9e9f14dd2f71
- https://lore.kernel.org/netdev/4d583fc5401298453d0a2f1b4719a15be30c8e49.1779194090.git.sd@queasysnail.net/
- https://lore.kernel.org/netdev/agVpIsaSherjHTYg@sultan-box/
- https://ubuntu.com/security/CVE-2026-46323
- https://git.kernel.org/linus/4db79a322db8c97f7b73b8a347395ef4d685eb40
- https://ubuntu.com/security/notices/USN-8440-1
- https://ubuntu.com/security/notices/USN-8461-1
- https://ubuntu.com/security/notices/USN-8489-1
- https://ubuntu.com/security/notices/USN-8497-1
- https://ubuntu.com/security/notices/USN-8499-1
- https://ubuntu.com/security/notices/USN-8569-1
- https://security-tracker.debian.org/tracker/CVE-2026-46323
- https://access.redhat.com/errata/RHSA-2026:62642
- https://access.redhat.com/errata/RHSA-2026:62639
- https://access.redhat.com/errata/RHSA-2026:62641
- https://access.redhat.com/errata/RHSA-2026:62640
- https://cert-portal.siemens.com/productcert/html/ssa-019113.html