---
id: CVE-2026-90115
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  xsk: fix NULL pointer dereference in __xsk_rcv()

  In the __xsk_rcv() multi-buffer path, xsk_buff_alloc() is called in a
  loop without checking its return value
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  xsk: fix NULL pointer dereference in __xsk_rcv()

  In the __xsk_rcv() multi-buffer path, xsk_buff_alloc() is called in a
  loop without checking its return value. xsk_buff…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 804627751b4281dd95148e7564759145da67855e <
    aaebce297efc3e3dccb98a6ff838cfaa47db08db
  - >-
    Linux >= 804627751b4281dd95148e7564759145da67855e <
    60d7d3559ce66e227e195e9463cdfed8077c8659
  - >-
    Linux >= 804627751b4281dd95148e7564759145da67855e <
    214fb79b0379cb0214905632a2537c0c33f594eb
  - >-
    Linux >= 804627751b4281dd95148e7564759145da67855e <
    8341bd3ff126d85bc8c4ed52eedcaa5b1a65f194
  - >-
    Linux >= 804627751b4281dd95148e7564759145da67855e <
    e37b2abca80473e106176e41712a369fd2f72117
  - Linux 6.6
published: '2026-09-17'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T17:17:03.623'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-90115'
references:
  - url: 'https://git.kernel.org/stable/c/214fb79b0379cb0214905632a2537c0c33f594eb'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/60d7d3559ce66e227e195e9463cdfed8077c8659'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/8341bd3ff126d85bc8c4ed52eedcaa5b1a65f194'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/aaebce297efc3e3dccb98a6ff838cfaa47db08db'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/e37b2abca80473e106176e41712a369fd2f72117'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-17T16:21:47.885Z'
epss: 0.00209
epssPercentile: 0.09751
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

xsk: fix NULL pointer dereference in __xsk_rcv()

In the __xsk_rcv() multi-buffer path, xsk_buff_alloc() is called in a
loop without checking its return value. xsk_buff_can_alloc() only
counts fill queue entries without validating their addresses, so it
can succeed while xsk_buff_alloc() rejects all remaining entries and
returns NULL.

  Oops: general protection fault, probably for non-canonical address
   0xdffffc0000000000
  KASAN: null-ptr-deref in range
   [0x0000000000000000-0x0000000000000007]
  RIP: 0010:__xsk_rcv+0x426/0xc20 (net/xdp/xsk.c:350)
  Call Trace:
   xsk_generic_rcv+0x26d/0x5f0
   xdp_do_generic_redirect+0x3c5/0xcf0
   do_xdp_generic+0x92f/0xe70
   __netif_receive_skb_core.constprop.0+0xf7e/0x2b30

Fix this with a two-stage transaction. First allocate and stage all
buffers required for the packet, recycling all staged buffers with
xsk_buff_free() if any allocation fails. Only after this stage
succeeds, copy the data, reserve the RX descriptors, and release the
buffers in an error-free loop.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
