CVE-2026-74476: veth: convert frag_list skbs before running XDP
In the Linux kernel, the following vulnerability has been resolved:
veth: convert fraglist skbs before running XDP
A fraglist skb can reach veth with datalen set but nrfrags zero. vethconvertskbtoxdpbuff() only converts skbs that are shared, locked, have frags[], or do not have enough headroom. It later uses skbisnonlinear() to decide whether to set XDPFLAGSHASFRAGS and xdpfragssize.
That exposes fraglist data to XDP as if it were stored in frags[], but frags[] is empty. AFXDP copy mode can then trust the bogus XDP fragment metadata, walk an empty fragment entry, and crash in memcpy() from xskrcv().
Route non-linear skbs through skbppcowdata() before exposing them to XDP, and only advertise XDP frags when the resulting skb has frags[]. skbcopybits() already handles fraglist input, and skbppcowdata() builds frags[] output with skbaddrxfrag(), which is the representation XDP multi-buffer expects.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-74476?
CVE-2026-74476 has a risk score of 55, indicating a moderate level of severity.
How do I fix CVE-2026-74476?
To fix CVE-2026-74476, update your Linux kernel to the latest version where the vulnerability has been resolved.
What is the impact of CVE-2026-74476 on my system?
CVE-2026-74476 could potentially allow mismanagement of skb data, impacting the performance and security of network operations.
Is CVE-2026-74476 exploitable in production environments?
Yes, if left unpatched, CVE-2026-74476 may be exploitable in production environments, hence prompt remediation is advised.
When was CVE-2026-74476 published?
CVE-2026-74476 was published on August 15, 2026.