AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-64566

CRITICAL · CVSS 9.8 EPSS 0.35%

Source: NVD + CISA KEV + EPSS · Published 2026-08-05 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's handling of fragment references in the iptfs_skb_add_frags() function, where the SKBFL_SHARED_FRAG flag is not properly propagated when copying fragment references. This oversight can lead to kernel-visible memory corruption, potentially causing system panics when the ESP attempts to decrypt data in place, overwriting memory still in use by the original SKB. System administrators and developers working with Linux kernel implementations should prioritize addressing this issue to prevent potential system instability and data integrity risks.

CVE
CVE-2026-64566
Severity
CRITICAL
CVSS
9.8
EPSS
0.35%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: xfrm: iptfs: propagate SKBFL_SHARED_FRAG in iptfs_skb_add_frags() When iptfs_skb_add_frags() copies frag references from the source frag walk into a new SKB, it increments the page reference count via __skb_frag_ref() but does not propagate SKBFL_SHARED_FRAG to the destination SKB's skb_shinfo->flags. If the source SKB carries shared frags (e.g. from a page-pool backed receive path), the new inner SKB will appear to ESP as having privately owned frags. A subsequent esp_input() call for a nested transport-mode SA then takes the no-COW fast path and decrypts in place, writing over pages that are still referenced by the outer IPTFS SKB. This causes kernel-visible memory corruption and can trigger a panic. All other frag-transfer helpers in the kernel (skb_try_coalesce, skb_gro_receive, __pskb_copy_fclone, skb_shift, skb_segment) correctly propagate SKBFL_SHARED_FRAG; align iptfs_skb_add_frags() with this convention by setting the flag inside the loop immediately after __skb_frag_ref() and nr_frags++, so every exit path that attaches a frag unconditionally propagates SKBFL_SHARED_FRAG.