CVE-2026-64566: xfrm: iptfs: propagate SKBFL_SHARED_FRAG in iptfs_skb_add_frags()
In the Linux kernel, the following vulnerability has been resolved:
xfrm: iptfs: propagate SKBFLSHAREDFRAG in iptfsskbaddfrags()
When iptfsskbaddfrags() copies frag references from the source frag walk into a new SKB, it increments the page reference count via skbfragref() but does not propagate SKBFLSHAREDFRAG to the destination SKB's skbshinfo->flags.
If the source SKB carries shared frags (e.g. from a page-pool backed receive path), the new inner SKB will appear to ESP as having privately owned frags. A subsequent espinput() call for a nested transport-mode SA then takes the no-COW fast path and decrypts in place, writing over pages that are still referenced by the outer IPTFS SKB. This causes kernel-visible memory corruption and can trigger a panic.
All other frag-transfer helpers in the kernel (skbtrycoalesce, skbgroreceive, pskbcopyfclone, skbshift, skbsegment) correctly propagate SKBFLSHAREDFRAG; align iptfsskbaddfrags() with this convention by setting the flag inside the loop immediately after skbfragref() and nrfrags++, so every exit path that attaches a frag unconditionally propagates SKBFLSHAREDFRAG.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-64566?
CVE-2026-64566 has a risk rating of 57.
What systems are affected by CVE-2026-64566?
CVE-2026-64566 affects the Linux kernel.
How do I fix CVE-2026-64566?
To fix CVE-2026-64566, you should update your Linux kernel to the latest patched version provided by your distribution.
What are the potential impacts of CVE-2026-64566?
The potential impact of CVE-2026-64566 is related to improper handling of SKB fragment references, which may lead to memory management issues.
When was CVE-2026-64566 published?
CVE-2026-64566 was published on August 5, 2026.