Improper control of a resource through its lifetime in Linux kernel - CVE-2026-90049
Published: September 16, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause data corruption.
The vulnerability exists due to improper resource lifetime management in skb_zerocopy() when processing a packet through Open vSwitch's OVS_ACTION_ATTR_USERSPACE path after skb_orphan_frags() fails. A remote attacker can trigger the error path to cause data corruption.
Affected software
How to mitigate CVE-2026-90049
External References
- https://git.kernel.org/stable/c/04dd250a78e268af3e7124beb1dc10ec1dd88d60
- https://git.kernel.org/stable/c/767ec2a65cc022d303b0c9c12811e7db22057341
- https://git.kernel.org/stable/c/8069643ae64dfdf634b6c78c7f622e5323031436
- https://git.kernel.org/stable/c/849bdb83123760a865bcb2970127f4c0b9423ba3
- https://git.kernel.org/stable/c/8ece906150128d5ec2462aabcc978c568433eca4
- https://git.kernel.org/stable/c/a13b1e80e5015cd732440b475c0ef443dc4a2157
- https://git.kernel.org/stable/c/bab5a851e44a3601d31f2aa8043f385bb50ac5d9
- https://git.kernel.org/stable/c/fb10e0e9b220a2eed08931a60dbaad9a2370c908