CVE-2026-43093
Description
In the Linux kernel, the following vulnerability has been resolved:
xsk: tighten UMEM headroom validation to account for tailroom and min frame
The current headroom validation in xdp_umem_reg() could leave us with insufficient space dedicated to even receive minimum-sized ethernet frame. Furthermore if multi-buffer would come to play then skb_shared_info stored at the end of XSK frame would be corrupted.
HW typically works with 128-aligned sizes so let us provide this value as bare minimum.
Multi-buffer setting is known later in the configuration process so besides accounting for 128 bytes, let us also take care of tailroom space upfront.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
30cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*+ 15 more
- cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*range: >=4.19.118,<4.20
- cpe:2.3:o:linux:linux_kernel:5.7:-:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:5.7:rc2:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:5.7:rc3:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:5.7:rc4:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:5.7:rc5:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:5.7:rc6:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:5.7:rc7:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:7.0:rc1:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:7.0:rc2:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:7.0:rc3:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:7.0:rc4:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:7.0:rc5:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:7.0:rc6:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:7.0:rc7:*:*:*:*:*:*
- (no CPE)
- osv-coords14 versionspkg:linux/kernelpkg:rpm/opensuse/dtb-aarch64&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/kernel-64kb&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/kernel-azure&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/kernel-default&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/kernel-default-base&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/kernel-docs&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/kernel-kvmsmall&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/kernel-obs-build&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/kernel-obs-qa&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/kernel-rt&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/kernel-source&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/kernel-syms&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/kernel-zfcpdump&distro=openSUSE%20Leap%2016.0
>= 5.7.0, < 5.10.258+ 13 more
- (no CPE)range: >= 5.7.0, < 5.10.258
- (no CPE)range: < 6.12.0-160000.36.1
- (no CPE)range: < 6.12.0-160000.36.1
- (no CPE)range: < 6.12.0-160000.36.1
- (no CPE)range: < 6.12.0-160000.36.1
- (no CPE)range: < 6.12.0-160000.36.1.160000.2.17
- (no CPE)range: < 6.12.0-160000.36.1
- (no CPE)range: < 6.12.0-160000.36.1
- (no CPE)range: < 6.12.0-160000.36.1
- (no CPE)range: < 6.12.0-160000.36.1
- (no CPE)range: < 6.12.0-160000.36.1
- (no CPE)range: < 6.12.0-160000.36.1
- (no CPE)range: < 6.12.0-160000.36.1
- (no CPE)range: < 6.12.0-160000.36.1
Patches
Vulnerability mechanics
References
8- git.kernel.org/stable/c/0ec4d3f6e6934deb843b561ae048cd17218e5ad1nvdPatch
- git.kernel.org/stable/c/6523bc1b40e69301f24c14338b762af4739d6d39nvdPatch
- git.kernel.org/stable/c/9ea6ba4f3195dcba6e8b3e7b2e748593b7cafb12nvdPatch
- git.kernel.org/stable/c/a03975beb9f6af0d8ac051e30b2abeabe618414fnvdPatch
- git.kernel.org/stable/c/a315e022a72d95ef5f1d4e58e903cb492b0ad931nvdPatch
- git.kernel.org/stable/c/1a6051cd7e3e4c54ff3854a43b638b9292af5e67nvd
- git.kernel.org/stable/c/5f123bc278bf4e3283d8606321bebbfd299f4384nvd
- git.kernel.org/stable/c/8769708add9eadeea8041a9761771bb715a87104nvd
News mentions
0No linked articles in our index yet.