{"id":"CVE-2026-98368","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nesp: downgrade zerocopy managed frags before mutating skb frags\n\nOn the out-of-place output path (esp->inplace == false) ESP rewrites the\nskb frag array: esp_output_hea…","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nesp: downgrade zerocopy managed frags before mutating skb frags\n\nOn the out-of-place output path (esp->inplace == false) ESP rewrites the\nskb frag array: esp_output_hea…","severity":"none","vendor":"Linux","product":"Linux","affected":["Linux >= 753f1ca4e1e50248a1b760c9774d6d6b354562cc < 2359264f377cdbdef2d95868cc8fb572949e48d3","Linux >= 753f1ca4e1e50248a1b760c9774d6d6b354562cc < 69a768c12398cada8528080332c822623fa7064d","Linux >= 753f1ca4e1e50248a1b760c9774d6d6b354562cc < 6508304ac2c8cdafca2f4ab915df8c707893e134","Linux >= 753f1ca4e1e50248a1b760c9774d6d6b354562cc < 6cab554f2c0f28773f712ed3a5479103f42ce844","Linux >= 753f1ca4e1e50248a1b760c9774d6d6b354562cc < 0d0845ee61c5df47cc68bc446501f48f71e8dcc6","Linux >= 753f1ca4e1e50248a1b760c9774d6d6b354562cc < f89416eb3db151170a6f3c6dfc5239d26cdce4d2","Linux 6.0"],"published":"2026-10-06","updated":"2026-10-06","sourceUpdated":"2026-10-06T09:18:31.130","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-98368","references":[{"url":"https://git.kernel.org/stable/c/0d0845ee61c5df47cc68bc446501f48f71e8dcc6","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2359264f377cdbdef2d95868cc8fb572949e48d3","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6508304ac2c8cdafca2f4ab915df8c707893e134","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/69a768c12398cada8528080332c822623fa7064d","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6cab554f2c0f28773f712ed3a5479103f42ce844","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f89416eb3db151170a6f3c6dfc5239d26cdce4d2","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-06T08:50:17.390Z","slug":"CVE-2026-98368","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nesp: downgrade zerocopy managed frags before mutating skb frags\n\nOn the out-of-place output path (esp->inplace == false) ESP rewrites the\nskb frag array: esp_output_head() appends a trailer frag and\nesp_output_tail() replaces the frags with a destination page, both\nreferenced with get_page().\n\nWhen the skb carries zerocopy managed frags (SKBFL_MANAGED_FRAG_REFS) the\npayload frags are owned by the ubuf and must not be referenced or\nunreferenced individually, but ESP mutates the frag array without ever\ndowngrading the skb.  This breaks the managed-frag invariant two ways:\n\n  - esp_ssg_unref() walks the source scatterlist and drops a page\n    reference for every frag, including the ubuf-owned payload frags,\n    pushing their refcount below the GUP pin bias while the pages are\n    still pinned, i.e. a use-after-free of the zerocopy pages;\n\n  - esp_output_tail() installs its destination page as frag 0 with\n    get_page() but leaves SKBFL_MANAGED_FRAG_REFS set, so\n    skb_release_data() takes the skip_unref branch and never drops that\n    reference, leaking the x->xfrag page at packet rate.\n\nFix this the way every other frag-mutating site does (__ip_append_data(),\n__ip6_append_data(), tcp_sendmsg_locked()) and call\nskb_zcopy_downgrade_managed() before ESP touches the frag array: it takes\na real reference on each existing frag and clears SKBFL_MANAGED_FRAG_REFS,\nso the per-frag unref in esp_ssg_unref() and the frag release in\nskb_release_data() are both balanced and no mixed-ownership frag array is\nleft behind.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}