CVE-2026-64355
In the Linux kernel, the following vulnerability has been resolved: bpf: Reject fragmented frames in devmap Devmap broadcast redirects clone the packet for all but the last destination.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.51%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
In the Linux kernel, the following vulnerability has been resolved: bpf: Reject fragmented frames in devmap Devmap broadcast redirects clone the packet for all but the last destination. For native XDP, that clone path copies only the linear xdp_frame data, while fragmented frames keep skb_shared_info in tailroom outside the linear area. Cloning such a frame leaves XDP_FLAGS_HAS_FRAGS set but without valid frag metadata, and the later free path can interpret uninitialized tail data as skb_shared_info, leading to an out-of-bounds access during frame return. Reject fragmented native XDP frames in dev_map_enqueue_clone(). Add the same restriction to the generic XDP clone path in dev_map_redirect_clone(). Generic XDP represents fragmented packets as nonlinear skbs, and rejecting them here keeps clone-based broadcast support aligned between native and generic XDP.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.51% probability · 42th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-125
- Affected
- linux/linux kernel
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
References
- https://git.kernel.org/stable/c/07a4c11ee8ef4abcb39d922e9e410ae269671cdfPatch
- https://git.kernel.org/stable/c/47baddc856ae7e93a565dd9deeb797999b179466Patch
- https://git.kernel.org/stable/c/51d07c12ca411e692c424ecdabf077f1e61a61bePatch
- https://git.kernel.org/stable/c/a9bb2d9c798cb62a4050a991c27b752770c33afePatch
- https://git.kernel.org/stable/c/aa496720618f1a6054f1c870bf10b4f6c99bf656Patch
- https://git.kernel.org/stable/c/bccbab36ff228e0825eb85d9b0f9b8434cd0a399Patch
- https://git.kernel.org/stable/c/c5b4f5efcb55c1af3fe44ff712d31b7fb098a831Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.