SB2026091664 - Improper control of a resource through its lifetime in Linux kernel core
Published: September 16, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper control of a resource through its lifetime (CVE-ID: CVE-2026-90049)
CWE-ID: CWE-664 - Improper control of a resource through its lifetime
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause data corruption.
The vulnerability exists due to improper resource lifetime management in skb_zerocopy() when processing a packet through Open vSwitch's OVS_ACTION_ATTR_USERSPACE path after skb_orphan_frags() fails. A remote attacker can trigger the error path to cause data corruption.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/04dd250a78e268af3e7124beb1dc10ec1dd88d60
- https://git.kernel.org/stable/c/767ec2a65cc022d303b0c9c12811e7db22057341
- https://git.kernel.org/stable/c/8069643ae64dfdf634b6c78c7f622e5323031436
- https://git.kernel.org/stable/c/849bdb83123760a865bcb2970127f4c0b9423ba3
- https://git.kernel.org/stable/c/8ece906150128d5ec2462aabcc978c568433eca4
- https://git.kernel.org/stable/c/a13b1e80e5015cd732440b475c0ef443dc4a2157
- https://git.kernel.org/stable/c/bab5a851e44a3601d31f2aa8043f385bb50ac5d9
- https://git.kernel.org/stable/c/fb10e0e9b220a2eed08931a60dbaad9a2370c908