Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: tap: free page on error paths in tap_get_user_xdp() tap_get_user_xdp() rejects a frame shorter than ETH_HLEN with -EINVAL, and returns -ENOMEM when build_skb() fails. Both paths jump to the err label without freeing the page that vhost_net_build_xdp() allocated for the frame. tap_sendmsg() discards the per-buffer return value and always returns 0, so vhost_tx_batch() takes the success path and never frees the page; each rejected frame in a batch leaks one page-frag chunk. Free the page on both error paths, before the skb is built. This is the tap counterpart of the same leak in tun_xdp_one().
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 4.20, < 5.10.259 |
References
- https://git.kernel.org/stable/c/18a84c35842e19cd3c5534d8cee73d31863f696dPatch
- https://git.kernel.org/stable/c/3bcf7aec6a9d16438f2cec29f5d7c8d5b8edf9b2Patch
- https://git.kernel.org/stable/c/3f52a86a482a69294c50a5a2a097bd6f4104990aPatch
- https://git.kernel.org/stable/c/8d03e65eb6cfbffec471a6b65416f93679bf3286Patch
- https://git.kernel.org/stable/c/d30aac0fa00ca0afc3e08174cf7f974a66bdcf05Patch
- https://git.kernel.org/stable/c/d68eab61944a9b0826fa2e954e42db1aa3201b7aPatch
- https://git.kernel.org/stable/c/e27c17346628cb56843a83f93ac63c314c00f388Patch
- https://git.kernel.org/stable/c/f979971835dddbca86cf99e3b2e2b94a408a1ab2Patch
FAQ
What is CVE-2026-46320?
CVE-2026-46320 is a vulnerability with a CVSS score of 7.4 (HIGH). In the Linux kernel, the following vulnerability has been resolved: tap: free page on error paths in tap_get_user_xdp() tap_get_user_xdp() rejects a frame shorter than ETH_HLEN with -EINVAL, and ret...
How severe is CVE-2026-46320?
CVE-2026-46320 has been rated HIGH with a CVSS base score of 7.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-46320?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.