CVE-2026-53215: net: mvpp2: refill RX buffers before XDP or skb use
In the Linux kernel, the following vulnerability has been resolved:
Other sources
net: mvpp2: refill RX buffers before XDP or skb use
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.6.143.1-1 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.1.176-1Fixed in 6.1.187-1Fixed in 6.12.107-1Fixed in 7.2.6-1Fixed in 7.2.7-1 - Compensating control
In the mvpp2 RX path, refill the BM pool before handing the current buffer to XDP or an skb. If allocation/refill fails, drop the packet and return the still-owned current buffer to the BM pool, preserving pool depth; after successful refill, local drops must retire/free the current buffer instead of returning it to BM.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-53215?
CVE-2026-53215 has a critical severity rating of 9.8.
How do I fix CVE-2026-53215?
Fix CVE-2026-53215 by updating to the patched version of the Linux kernel provided by your distribution.
What type of vulnerability is CVE-2026-53215?
CVE-2026-53215 is a buffer handling vulnerability in the Linux kernel's mvpp2 driver.
Who is affected by CVE-2026-53215?
CVE-2026-53215 affects users running vulnerable versions of the Linux kernel on supported distributions.
What are the potential impacts of CVE-2026-53215?
Exploitation of CVE-2026-53215 may allow an attacker to compromise the confidentiality, integrity, and availability of the affected system.