Improper control of a resource through its lifetime in Linux kernel - CVE-2026-43039
Published: May 2, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local attacker to cause memory corruption.
The vulnerability exists due to improper resource management in emac_dispatch_skb_zc() when recycling an skb backed by the NAPI page frag allocator. A local attacker can trigger packet processing to cause memory corruption.
The issue occurs because a non-page_pool skb is marked for recycle, causing the free path to return pages to a page_pool that does not own them.