Skip to main content

In the Linux kernel, the following vulnerability has been resolved: xdp: fix zero-copy frame layout xdp_convert_zc_to_xdp_frame() clones an XSK… (CVE-2026-81002)

0
High
Published: 09/11/2026 (09/11/2026, 21:31:24 UTC)
Source: GCVE Database

Description

A vulnerability in the Linux kernel's XDP zero-copy frame layout was resolved. The function xdp_convert_zc_to_xdp_frame() improperly clones an XSK packet into an order-0 page, causing the copied frame to overlap or misplace skb_shared_info metadata. This can lead to out-of-bounds memory writes and kernel panics triggered by KASAN. The fix limits the copied layout size and correctly accounts for metadata length in frame headroom.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/12/2026, 01:19:34 UTC

Technical Analysis

The Linux kernel vulnerability CVE-2026-81002 involves the xdp_convert_zc_to_xdp_frame() function, which clones an AF_XDP zero-copy packet into an order-0 page and advertises PAGE_SIZE as the frame size. This allows the copied frame to occupy the page tail needed by skb_shared_info or to place it beyond the allocated page, resulting in overlapping or out-of-bounds memory access. This flaw can cause a slab-out-of-bounds write detected by KASAN and lead to kernel panics. The patch restricts the copied layout to SKB_WITH_OVERHEAD(PAGE_SIZE) and includes metadata length in the frame headroom to prevent these issues.

Potential Impact

The vulnerability can cause out-of-bounds memory writes within the kernel memory allocator slab, potentially leading to kernel panics and system instability. This affects the AF_XDP zero-copy packet processing path and can disrupt normal network packet handling. There is no indication of remote code execution or privilege escalation from the provided data.

Mitigation Recommendations

A fix has been implemented in the Linux kernel to address this vulnerability by limiting the copied frame layout size and properly accounting for metadata length. Users should apply the official kernel updates that include this patch. No additional mitigation steps are indicated or required beyond applying the fix.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-w4xj-mpx6-w45f
Osv Schema Version
1.4.0
Aliases
["CVE-2026-81002"]

Threat ID: 6aa4a02755bf5e2cf5a86b09

Added to database: 09/12/2026, 00:43:19 UTC

Last enriched: 09/12/2026, 01:19:34 UTC

Last updated: 09/12/2026, 01:19:34 UTC

Views: 2

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses