Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

CVE-2026-53216

net: mvpp2: limit XDP frame size to the RX buffer
Back to all
CVE

CVE-2026-53216

net: mvpp2: limit XDP frame size to the RX buffer

In the Linux kernel, the following vulnerability has been resolved:

net: mvpp2: limit XDP frame size to the RX buffer

mvpp2 has short and long BM pools, and short pool buffers can be smaller

than PAGESIZE. The XDP path nevertheless initializes every xdpbuff with

PAGE_SIZE as frame size.

XDP helpers use frame_sz to validate tail growth and to derive the hard

end of the data area. Advertising PAGE_SIZE for short buffers can let

bpfxdpadjust_tail() grow a packet past the real allocation, corrupting

memory or later tripping skb tailroom checks.

Initialize the XDP buffer with bmpool->fragsize so XDP tailroom matches

the actual buffer backing the packet.

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
9.8
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
0
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
-

Related Resources

No items found.

References

https://git.kernel.org/stable/c/3b8b0c3631b19faee53f0d15a49924129b063eec, https://git.kernel.org/stable/c/910617a4e67dbdd5fdb39d9dc6a51e491e1b2c3e, https://git.kernel.org/stable/c/9545cc5ef18ca22d031f2f47c157192460652359, https://git.kernel.org/stable/c/994bd2b58d2bd08aa97ec0836cc813cfcb00d749, https://git.kernel.org/stable/c/a3ee9231ccec6ec3be2de89c56f897055fd9eab1, https://git.kernel.org/stable/c/ec8e1e5842bc0dbd4c272761f4db3651eecd0339, https://git.kernel.org/stable/c/f3c6aa078927e6fe8121c9c591ddee8716c5305a, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/53xxx/CVE-2026-53216.json, https://nvd.nist.gov/vuln/detail/CVE-2026-53216, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Severity

9.8

CVSS Score
0
10

Basic Information

Base CVSS
9.8
EPSS Probability
0.00546%
EPSS Percentile
0.41822%
Introduced Version
07dd0a7aae7f72af7cec18909581c2bb570edddc,5.9.0,5.16.0,6.2.0,6.7.0,6.13.0,6.19.0,0
Fix Available
f3c6aa078927e6fe8121c9c591ddee8716c5305a,5.15.210,6.1.176,6.6.143,6.12.94,6.18.36,7.0.13,6.1.176-1,6.12.94-1,6.1.176-1~deb11u1,6.12.95-r0,6.18.38-r0

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading