---
id: CVE-2026-53250
title: 'xsk: cache csum_start/csum_offset to fix TOCTOU in xsk_skb_metadata()'
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  xsk: cache csum_start/csum_offset to fix TOCTOU in xsk_skb_metadata()

  The TX metadata area resides in the UMEM buffer which is memory-mapped
  and concurrently writable …
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cvssSource: cna
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 48eb03dd26304c24f03bdbb9382e89c8564e71df <
    eb778aed8a9b2381668fcb1247ae4fa011224768
  - >-
    Linux >= 48eb03dd26304c24f03bdbb9382e89c8564e71df <
    0dfe05b938435892875e07771170051346412df9
  - >-
    Linux >= 48eb03dd26304c24f03bdbb9382e89c8564e71df <
    bfdfd2706d5fb2cd496a1506e680daf979309c8b
  - >-
    Linux >= 48eb03dd26304c24f03bdbb9382e89c8564e71df <
    22ba97ea9cc1f63a0d0244fae38057ed452b6ac7
  - Linux 6.8
published: '2026-06-25'
updated: '2026-09-14'
sourceUpdated: '2026-09-14T11:58:33.282Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2026-53250'
references:
  - url: 'https://git.kernel.org/stable/c/eb778aed8a9b2381668fcb1247ae4fa011224768'
  - url: 'https://git.kernel.org/stable/c/0dfe05b938435892875e07771170051346412df9'
  - url: 'https://git.kernel.org/stable/c/bfdfd2706d5fb2cd496a1506e680daf979309c8b'
  - url: 'https://git.kernel.org/stable/c/22ba97ea9cc1f63a0d0244fae38057ed452b6ac7'
tags:
  - cve.org
epss: 0.00104
epssPercentile: 0.00958
ingestedAt: '2026-09-14T15:23:07.457Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

xsk: cache csum_start/csum_offset to fix TOCTOU in xsk_skb_metadata()

The TX metadata area resides in the UMEM buffer which is memory-mapped
and concurrently writable by userspace. In xsk_skb_metadata(),
csum_start and csum_offset are read from shared memory for bounds
validation, then read again for skb assignment. A malicious userspace
application can race to overwrite these values between the two reads,
bypassing the bounds check and causing out-of-bounds memory access
during checksum computation in the transmit path.

Fix this by reading csum_start and csum_offset into local variables
once, then using the local copies for both validation and assignment.

Note that other metadata fields (flags, launch_time) and the cached
csum fields may be mutually inconsistent due to concurrent userspace
writes, but this is benign: the only security-critical invariant is
that each field's validated value is the same one used, which local
caching guarantees.

## Affected

- `Linux >= 48eb03dd26304c24f03bdbb9382e89c8564e71df < eb778aed8a9b2381668fcb1247ae4fa011224768`
- `Linux >= 48eb03dd26304c24f03bdbb9382e89c8564e71df < 0dfe05b938435892875e07771170051346412df9`
- `Linux >= 48eb03dd26304c24f03bdbb9382e89c8564e71df < bfdfd2706d5fb2cd496a1506e680daf979309c8b`
- `Linux >= 48eb03dd26304c24f03bdbb9382e89c8564e71df < 22ba97ea9cc1f63a0d0244fae38057ed452b6ac7`
- `Linux 6.8`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
