{"id":"CVE-2026-46331","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: fix pedit partial COW leading to page cache corruption\n\ntcf_pedit_act() computes the COW range for skb_ensure_writable()\nonce before the key loop using tcfp_…","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: fix pedit partial COW leading to page cache corruption\n\ntcf_pedit_act() computes the COW range for skb_ensure_writable()\nonce before the key loop using tcfp_…","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-190","CWE-787"],"published":"2026-06-16","updated":"2026-06-29","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-46331","references":[{"url":"https://git.kernel.org/stable/c/2bec122b9fb91507a758ab5e3e5c4fbe7cb3f61b","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3dee9d0c198faeb95d052c1b94c2958751a28512","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/899ee91156e57784090c5565e4f31bd7dbffbc5a","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b198ed4e52580a7238c7c7082f03906f8b310313","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://github.com/sgkdev/packet_edit_meme/tree/main","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://git.kernel.org/stable/c/544d857b42a1734b923040e13aa61a6fd4746cf2"},{"url":"https://git.kernel.org/stable/c/d5d01d35a5a7d36f7cb679b67d9cbdd5205672dc"},{"url":"https://git.kernel.org/stable/c/a071e057518decc5e3bec89855758f5f8786f2c5"},{"url":"https://git.kernel.org/stable/c/b685d6ef6f07a3b5ce814565a25f39f2157538a5"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-46331.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-46331"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2479492"},{"url":"https://access.redhat.com/security/vulnerabilities/RHSB-2026-008"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-46331"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-46331"},{"url":"https://lore.kernel.org/netdev/20260516162825.1480113-1-rollkingzzc@gmail.com/"},{"url":"https://access.redhat.com/errata/RHSA-2026:27709"},{"url":"https://access.redhat.com/errata/RHSA-2026:33666"},{"url":"https://access.redhat.com/errata/RHSA-2026:34048"},{"url":"https://access.redhat.com/errata/RHSA-2026:40021"},{"url":"https://access.redhat.com/errata/RHSA-2026:28887"},{"url":"https://access.redhat.com/errata/RHSA-2026:28962"},{"url":"https://access.redhat.com/errata/RHSA-2026:29080"},{"url":"https://access.redhat.com/errata/RHSA-2026:34098"},{"url":"https://access.redhat.com/errata/RHSA-2026:29856"},{"url":"https://access.redhat.com/errata/RHSA-2026:29863"},{"url":"https://access.redhat.com/errata/RHSA-2026:29799"},{"url":"https://access.redhat.com/errata/RHSA-2026:29833"},{"url":"https://access.redhat.com/errata/RHSA-2026:29794"},{"url":"https://access.redhat.com/errata/RHSA-2026:27731"},{"url":"https://access.redhat.com/errata/RHSA-2026:27288"},{"url":"https://access.redhat.com/errata/RHSA-2026:27705"},{"url":"https://access.redhat.com/errata/RHSA-2026:27713"},{"url":"https://access.redhat.com/errata/RHSA-2026:27708"},{"url":"https://access.redhat.com/errata/RHSA-2026:27789"},{"url":"https://access.redhat.com/errata/RHSA-2026:33225"},{"url":"https://access.redhat.com/errata/RHSA-2026:27353"},{"url":"https://access.redhat.com/errata/RHSA-2026:33220"},{"url":"https://access.redhat.com/errata/RHSA-2026:27707"}],"tags":["nvd","exploit-available","cve.org","csaf","vex","red-hat"],"epss":0.00583,"epssPercentile":0.46322,"ingestedAt":"2026-06-29T15:48:27.678Z","exploits":{"github":14,"githubRepos":["https://github.com/sgkdev/packet_edit_meme","https://github.com/0xBlackash/CVE-2026-46331","https://github.com/rjt-gupta/page-cache-corruption-lpes"],"checkedAt":"2026-09-21T15:29:09.502Z"},"exploitAvailable":true,"vendor":"Linux","product":"Linux","affected":["Linux >= abe35bf3be51482593076d516a680d79e5fbc8e1 < 544d857b42a1734b923040e13aa61a6fd4746cf2","Linux >= b773640d5bb9e2acfd91e2695717af04d47aa116 < d5d01d35a5a7d36f7cb679b67d9cbdd5205672dc","Linux >= 8b796475fd7882663a870456466a4fb315cc1bd6 < a071e057518decc5e3bec89855758f5f8786f2c5","Linux >= 8b796475fd7882663a870456466a4fb315cc1bd6 < b685d6ef6f07a3b5ce814565a25f39f2157538a5","Linux >= 8b796475fd7882663a870456466a4fb315cc1bd6 < 2bec122b9fb91507a758ab5e3e5c4fbe7cb3f61b","Linux >= 8b796475fd7882663a870456466a4fb315cc1bd6 < b198ed4e52580a7238c7c7082f03906f8b310313","Linux >= 8b796475fd7882663a870456466a4fb315cc1bd6 < 3dee9d0c198faeb95d052c1b94c2958751a28512","Linux >= 8b796475fd7882663a870456466a4fb315cc1bd6 < 899ee91156e57784090c5565e4f31bd7dbffbc5a","Linux d0c38a914b0c4c21d553da801003d36979016726","Linux 2ec2dd7d51a9320151f275ddbb2b53260fb32ca1","Linux c19cc520b3d69904e9518d401ad0df7f4702aca0","Linux >= 5.10.117 < 5.10.260","Linux >= 5.15.41 < 5.15.211","Linux >= 4.19.244 < 4.20","Linux >= 5.4.195 < 5.5","Linux >= 5.17.9 < 5.18","Linux 5.18"],"ssvc":{"exploitation":"poc","automatable":"no","technicalImpact":"total","timestamp":"2026-06-29T00:00:00+00:00"},"patched":["nvidia_for_rhel 10","openshift_container_platform 4.12","openshift_container_platform 4.13","openshift_container_platform 4.14","openshift_container_platform 4.15","openshift_container_platform 4.16","openshift_container_platform 4.17","openshift_container_platform 4.18","openshift_container_platform 4.19","openshift_container_platform 4.20","openshift_container_platform 4.21","openshift_container_platform 4.22","enterprise_linux_appstream_eus_v_10_0","enterprise_linux_appstream_v_10","enterprise_linux_appstream_e4s_v_9_2","enterprise_linux_appstream_e4s_v_9_4","enterprise_linux_appstream_eus_v_9_6","enterprise_linux_appstream_v_9","enterprise_linux_baseos_eus_v_10_0","enterprise_linux_baseos_v_10","enterprise_linux_baseos_v_8","enterprise_linux_baseos_aus_v_8_4","enterprise_linux_baseos_eus_extension_v_8_4","enterprise_linux_baseos_aus_v_8_6","enterprise_linux_baseos_eus_extension_v_8_6","enterprise_linux_baseos_e4s_v_8_8","enterprise_linux_baseos_tus_v_8_8","enterprise_linux_baseos_e4s_v_9_2","enterprise_linux_baseos_e4s_v_9_4","enterprise_linux_baseos_eus_v_9_6","enterprise_linux_baseos_v_9","enterprise_linux_codeready_linux_builder_eus_v_10_0","enterprise_linux_codeready_linux_builder_v_10","enterprise_linux_crb_v_8","codeready_linux_builder_eus_v_9_6","enterprise_linux_codeready_linux_builder_v_9","enterprise_linux_real_time_for_nfv_eus_v_10_0","enterprise_linux_real_time_for_nfv_v_10","enterprise_linux_nfv_v_8","enterprise_linux_real_time_for_nfv_e4s_v_9_2"],"scores":{"nvd":7.8,"vendor":6.7},"slug":"CVE-2026-46331","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: fix pedit partial COW leading to page cache corruption\n\ntcf_pedit_act() computes the COW range for skb_ensure_writable()\nonce before the key loop using tcfp_off_max_hint, but the hint does\nnot account for the runtime header offset added by typed keys. This\ncan leave part of the write region un-COW'd.\n\nFix by moving skb_ensure_writable() inside the per-key loop where\nthe actual write offset is known, and add overflow checking on the\noffset arithmetic. For negative offsets (e.g. Ethernet header edits\nat ingress), use skb_cow() to COW the headroom instead. Guard\noffset_valid() against INT_MIN, where negation is undefined.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Vendor advisories\n\n- **RHSA-2026:27709** · Red Hat · fixed in: NVIDIA for RHEL 10 · released 2026-06-22 · [advisory](https://access.redhat.com/errata/RHSA-2026:27709)\n- **RHSA-2026:33666** · Red Hat · fixed in: NVIDIA for RHEL 10 · released 2026-06-30 · [advisory](https://access.redhat.com/errata/RHSA-2026:33666)\n- **RHSA-2026:34048** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.12 · released 2026-07-09 · [advisory](https://access.redhat.com/errata/RHSA-2026:34048)\n- **RHSA-2026:40021** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.13 · released 2026-07-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:40021)\n- **RHSA-2026:28887** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.14 · released 2026-07-01 · [advisory](https://access.redhat.com/errata/RHSA-2026:28887)\n- **RHSA-2026:28962** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.15 · released 2026-07-06 · [advisory](https://access.redhat.com/errata/RHSA-2026:28962)\n- **RHSA-2026:29080** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.16 · released 2026-07-01 · [advisory](https://access.redhat.com/errata/RHSA-2026:29080)\n- **RHSA-2026:34098** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.17 · released 2026-07-09 · [advisory](https://access.redhat.com/errata/RHSA-2026:34098)\n- **RHSA-2026:29856** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.18 · released 2026-07-01 · [advisory](https://access.redhat.com/errata/RHSA-2026:29856)\n- **RHSA-2026:29863** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.19 · released 2026-07-02 · [advisory](https://access.redhat.com/errata/RHSA-2026:29863)\n- **RHSA-2026:29799** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.20 · released 2026-06-30 · [advisory](https://access.redhat.com/errata/RHSA-2026:29799)\n- **Red Hat VEX** · Important · affected: Red Hat OpenShift Container Platform 4 · no fix planned: Red Hat OpenShift Container Platform 4 · updated 2026-09-14 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-46331.json)","depth":"midnight","depthScore":55,"depthScoreParts":{"impact":42.9,"likelihood":0.1,"exploitation":12,"ransomware":0},"changes":[{"seq":5250,"id":"CVE-2026-46331","ts":1788887256795,"field":"exploit_available","old":"false","new":"true"},{"seq":4133,"id":"CVE-2026-46331","ts":1788886373230,"field":"exploit_available","old":"true","new":"false"},{"seq":2906,"id":"CVE-2026-46331","ts":1788883039132,"field":"exploit_available","old":"false","new":"true"},{"seq":1935,"id":"CVE-2026-46331","ts":1788882442152,"field":"exploit_available","old":"true","new":"false"},{"seq":1024,"id":"CVE-2026-46331","ts":1788881876869,"field":"exploit_available","old":"false","new":"true"}]}