In the Linux kernel, the following vulnerability has been resolved: xdp: fix zero-copy frame layout xdp_convert_zc_to_xdp_frame() clones an XSK… (CVE-2026-81002)
A vulnerability in the Linux kernel's XDP zero-copy frame layout was resolved. The function xdp_convert_zc_to_xdp_frame() improperly clones an XSK packet into an order-0 page, causing the copied frame to overlap or misplace skb_shared_info metadata. This can lead to out-of-bounds memory writes and kernel panics triggered by KASAN. The fix limits the copied layout size and correctly accounts for metadata length in frame headroom.
AI Analysis
Technical Summary
The Linux kernel vulnerability CVE-2026-81002 involves the xdp_convert_zc_to_xdp_frame() function, which clones an AF_XDP zero-copy packet into an order-0 page and advertises PAGE_SIZE as the frame size. This allows the copied frame to occupy the page tail needed by skb_shared_info or to place it beyond the allocated page, resulting in overlapping or out-of-bounds memory access. This flaw can cause a slab-out-of-bounds write detected by KASAN and lead to kernel panics. The patch restricts the copied layout to SKB_WITH_OVERHEAD(PAGE_SIZE) and includes metadata length in the frame headroom to prevent these issues.
Potential Impact
The vulnerability can cause out-of-bounds memory writes within the kernel memory allocator slab, potentially leading to kernel panics and system instability. This affects the AF_XDP zero-copy packet processing path and can disrupt normal network packet handling. There is no indication of remote code execution or privilege escalation from the provided data.
Mitigation Recommendations
A fix has been implemented in the Linux kernel to address this vulnerability by limiting the copied frame layout size and properly accounting for metadata length. Users should apply the official kernel updates that include this patch. No additional mitigation steps are indicated or required beyond applying the fix.
In the Linux kernel, the following vulnerability has been resolved: xdp: fix zero-copy frame layout xdp_convert_zc_to_xdp_frame() clones an XSK… (CVE-2026-81002)
Description
A vulnerability in the Linux kernel's XDP zero-copy frame layout was resolved. The function xdp_convert_zc_to_xdp_frame() improperly clones an XSK packet into an order-0 page, causing the copied frame to overlap or misplace skb_shared_info metadata. This can lead to out-of-bounds memory writes and kernel panics triggered by KASAN. The fix limits the copied layout size and correctly accounts for metadata length in frame headroom.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Linux kernel vulnerability CVE-2026-81002 involves the xdp_convert_zc_to_xdp_frame() function, which clones an AF_XDP zero-copy packet into an order-0 page and advertises PAGE_SIZE as the frame size. This allows the copied frame to occupy the page tail needed by skb_shared_info or to place it beyond the allocated page, resulting in overlapping or out-of-bounds memory access. This flaw can cause a slab-out-of-bounds write detected by KASAN and lead to kernel panics. The patch restricts the copied layout to SKB_WITH_OVERHEAD(PAGE_SIZE) and includes metadata length in the frame headroom to prevent these issues.
Potential Impact
The vulnerability can cause out-of-bounds memory writes within the kernel memory allocator slab, potentially leading to kernel panics and system instability. This affects the AF_XDP zero-copy packet processing path and can disrupt normal network packet handling. There is no indication of remote code execution or privilege escalation from the provided data.
Mitigation Recommendations
A fix has been implemented in the Linux kernel to address this vulnerability by limiting the copied frame layout size and properly accounting for metadata length. Users should apply the official kernel updates that include this patch. No additional mitigation steps are indicated or required beyond applying the fix.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-w4xj-mpx6-w45f
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-81002"]
Threat ID: 6aa4a02755bf5e2cf5a86b09
Added to database: 09/12/2026, 00:43:19 UTC
Last enriched: 09/12/2026, 01:19:34 UTC
Last updated: 09/12/2026, 01:19:34 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.