Back

HIGH

rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present

Published May 11, 2026

Description

The DATA-packet handler in rxrpc_input_call_event() and the RESPONSE handler in rxrpc_verify_response() copy the skb to a linear one before calling into the security ops only when skb_cloned() is true. An skb that is not cloned but still carries externally-owned paged fragments (e.g. SKBFL_SHARED_FRAG set by splice() into a UDP socket via __ip_append_data, or a chained skb_has_frag_list()) falls through to the in-place decryption path, which binds the frag pages directly into the AEAD/skcipher SGL via skb_to_sgvec().

Extend the gate to also unshare when skb_has_frag_list() or skb_has_shared_frag() is true. This catches the splice-loopback vector and other externally-shared frag sources while preserving the zero-copy fast path for skbs whose frags are kernel-private (e.g. NIC page_pool RX, GRO). The OOM/trace handling already in place is reused.

Affected products

Remediation

Red Hat statement

This issue is classified as Important, rather than Critical severity, because exploitation requires local access to the system. A low-privileged local attacker can exploit this flaw in the Linux kernel's RxRPC subsystem to gain root privileges by overwriting sensitive system files. Exploitation does not require user interaction, potentially resulting in full compromise of confidentiality, integrity, and availability. While the kernel source RPM for Red Hat Enterprise Linux 9 and 10 includes the `rxrpc` module in its build configuration, the binary RPMs that provide this module are not shipped or supported by Red Hat. The module is not installed by default and is not included in any other kernel binary package. For OpenShift Container Platform 4, the RPMs are not included in Red Hat Enterprise Linux CoreOS (RHCOS) images and is not installable through any supported cluster workflow.

Red Hat mitigation

See the security bulletin for a detailed mitigation procedure.

Metrics

References (12)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Linux
Published May 11, 2026
Updated Sep 1, 2026
Reserved May 1, 2026
CISA Vulnrichment
Updated May 11, 2026
NVD
Status Modified
Modified Aug 24, 2026
Red Hat
Severity Important
Public date May 11, 2026