CVE-2026-81002
In the Linux kernel, the following vulnerability has been resolved:
xdp: fix zero-copy frame layout
xdpconvertzctoxdp_frame() clones an XSK packet into an order-0 page
and advertises PAGE_SIZE as its frame size. It allows the copied frame
to occupy the page tail needed by skbsharedinfo and records zero
headroom even when metadata separates the frame header from packet data.
An AF_XDP zero-copy packet redirected through cpumap can therefore make
the skb overlap skbsharedinfo or place it beyond the allocated page.
Limit the copied layout to SKBWITHOVERHEAD(PAGE_SIZE) and include the
metadata length in frame headroom. Redirect callers already handle a
NULL conversion result.
BUG: KASAN: slab-out-of-bounds in skbgroreceive
Write of size 4 at addr ffff88800cf37004 by task cpumap/1/map:1/146
Call Trace:
skbgroreceive (net/core/gro.c:174)
udpgroreceive (net/ipv4/udp_offload.c:812)
inetgroreceive (net/ipv4/af_inet.c:1539)
devgroreceive (net/core/gro.c:515)
groreceiveskb (net/core/gro.c:633)
cpumapkthread_run (kernel/bpf/cpumap.c:395)
kthread (kernel/kthread.c:436)
retfromfork (arch/x86/kernel/process.c:164)
retfromforkasm (arch/x86/entry/entry64.S:255)
Kernel panic - not syncing: KASAN: paniconwarn set ...
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://git.kernel.org/stable/c/15d1f3c0dbe7a740f779337deb39f23cd8d002c8, https://git.kernel.org/stable/c/22092730129077c302d8c947bbe0876f0280c528, https://git.kernel.org/stable/c/444216dacdbebd3e52d5e704facafbb230da09e9, https://git.kernel.org/stable/c/68d7cc5512238693670fc19c7a615df631e10edf, https://git.kernel.org/stable/c/6de17275b3ccdf9887568b07e54da2e3597217cf, https://git.kernel.org/stable/c/71283aaa6c65b3cec84caf1dc78560985737641f, https://git.kernel.org/stable/c/ced3e18cd9b9caf630aaa1e1eac305f5192ba896, https://git.kernel.org/stable/c/dcb6db9ca6515fcd3e00c93ec5e27dc7a0a7012f, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/81xxx/CVE-2026-81002.json, https://nvd.nist.gov/vuln/detail/CVE-2026-81002, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git