CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-46300

High · CVSS 7.8

Linux Kernel — Out-of-bounds write / arbitrary write via lost shared-frag marker during SKB coalescing (CWE-787, CWE-123)

CVSS
7.8
nvd
EPSS
KEV
No
Class
oss containerizable
CWE-787, CWE-123

Description

In the Linux kernel, the following vulnerability has been resolved: net: skbuff: preserve shared-frag marker during coalescing skb_try_coalesce() can attach paged frags from @from to @to. If @from has SKBFL_SHARED_FRAG set, the resulting @to skb can contain the same externally-owned or page-cache-backed frags, but the shared-frag marker is currently lost. That breaks the invariant relied on by later in-place writers. In particular, ESP input checks skb_has_shared_frag() before deciding whether an uncloned nonlinear skb can skip skb_cow_data(). If TCP receive coalescing has moved shared frags into an unmarked skb, ESP can see skb_has_shared_frag() as false and decrypt in place over page-cache backed frags. Propagate SKBFL_SHARED_FRAG when skb_try_coalesce() transfers paged frags. The tailroom copy path does not need the marker because it copies bytes into @to's linear data rather than transferring frag descriptors.

Search profile — drives PoC discovery

Symbols skb_try_coalesceSKBFL_SHARED_FRAGskb_has_shared_fragskb_cow_dataskbuffnet/core/skbuff.cSKBFL_SHARED_FRAG propagateESP inputTCP receive coalescingpaged fragsskb_shinfo
Keywords CVE-2026-46300skb_try_coalesce SKBFL_SHARED_FRAGLinux kernel skbuff shared frag coalesceESP decrypt in-place page-cache fragskb_has_shared_frag bypassskbuff coalescing out-of-bounds writeLinux kernel net skbuff PoCSKBFL_SHARED_FRAG marker lost coalesceTCP coalescing ESP shared frag vulnerability
Versions: Linux kernel versions prior to stable commits: 2f2b16022a2e, 3599e6b3cc1a, 3884358a9286, 3bd9e113d500, 760e1addc27b

Ranked PoCs (12) — best first

Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.

Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.

Affected packages

Linux Kernel 3.9.0 → 5.10.257
Linux Kernel 5.11.0 → 5.15.208
Linux Kernel 5.16.0 → 6.1.174
Linux Kernel 6.13.0 → 6.18.33
Linux Kernel 6.19.0 → 7.0.10
Linux Kernel 6.2.0 → 6.6.141
Linux Kernel 6.7.0 → 6.12.91

References

Status: enriched · ingested 2026-07-10T18:00:26.000Z · profiled 2026-07-10T18:30:26.000Z