net/sched: fix pedit partial COW leading to page cache corruption
Published Jun 16, 2026
7.8
HIGHCVSS 3.1
EPSS 0.20%
Description
tcf_pedit_act() computes the COW range for skb_ensure_writable() once before the key loop using tcfp_off_max_hint, but the hint does not account for the runtime header offset added by typed keys. This can leave part of the write region un-COW'd.
Fix by moving skb_ensure_writable() inside the per-key loop where the actual write offset is known, and add overflow checking on the offset arithmetic. For negative offsets (e.g. Ethernet header edits at ingress), use skb_cow() to COW the headroom instead. Guard offset_valid() against INT_MIN, where negation is undefined.
Affected products
-
- Version StatusaffectedConstraints-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints-
- Version StatusaffectedConstraints-
- Version
-
- Version 4.19.244StatusaffectedConstraints<4.20
- Version 5.10.117StatusaffectedConstraints<5.10.260
- Version 5.15.41StatusaffectedConstraints<5.15.211
- Version 5.17.9StatusaffectedConstraints<5.18
- Version 5.4.195StatusaffectedConstraints<5.5
- Version
-
- Version 5.18StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<5.18
- Version 5.10.260StatusunaffectedConstraints<=5.10.*
- Version 5.15.211StatusunaffectedConstraints<=5.15.*
- Version 6.1.177StatusunaffectedConstraints<=6.1.*
- Version 6.12.94StatusunaffectedConstraints<=6.12.*
- Version 6.18.36StatusunaffectedConstraints<=6.18.*
- Version 6.6.144StatusunaffectedConstraints<=6.6.*
- Version 7.0.13StatusunaffectedConstraints<=7.0.*
- Version 7.1StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| ||||||||||||||||||||||||||||||||||||
| Linux | Linux | unaffected |
| ||||||||||||||||||||||||||||||||||||
| Linux | Linux | affected |
|
- ≥ 4.19.244 · < 4.20
- ≥ 5.4.195 · < 5.5
- ≥ 5.10.117 · < 5.11
- ≥ 5.15.41 · < 5.16
- ≥ 5.17.9 · < 5.18
- ≥ 5.18.1 · < 6.12.94
- ≥ 6.13 · < 6.18.36
- ≥ 6.19 · < 7.0.13
- 5.18
- 5.18
- 7.1
- 7.1
- 7.1
- 7.1
- 7.1
- 7.1
No data.
NVIDIA for RHEL 10
kernel-0:6.12.0-212.11.el10nv
Fixed · RHSA-2026:27709
NVIDIA for RHEL 10
kernel-0:6.12.0-231.13.el10nv
Fixed · RHSA-2026:33666
Red Hat Enterprise Linux 10
kernel-0:6.12.0-211.26.1.el10_2
Fixed · RHSA-2026:27288
Red Hat Enterprise Linux 10
kpatch-patch
Fixed · RHSA-2026:33225
Red Hat Enterprise Linux 10.0 Extended Update Support
kernel-0:6.12.0-55.82.1.el10_0
Fixed · RHSA-2026:27731
Red Hat Enterprise Linux 8
kernel-0:4.18.0-553.136.1.el8_10
Fixed · RHSA-2026:27353
Red Hat Enterprise Linux 8
kernel-rt-0:4.18.0-553.136.1.rt7.477.el8_10
Fixed · RHSA-2026:27354
Red Hat Enterprise Linux 8
kpatch-patch
Fixed · RHSA-2026:33220
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
kernel-0:4.18.0-305.195.1.el8_4
Fixed · RHSA-2026:27707
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
kernel-0:4.18.0-305.195.1.el8_4
Fixed · RHSA-2026:27707
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
kernel-0:4.18.0-372.197.1.el8_6
Fixed · RHSA-2026:27704
Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On
kernel-0:4.18.0-372.197.1.el8_6
Fixed · RHSA-2026:27704
Red Hat Enterprise Linux 8.8 Telecommunications Update Service
kernel-0:4.18.0-477.148.1.el8_8
Fixed · RHSA-2026:27355
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
kernel-0:4.18.0-477.148.1.el8_8
Fixed · RHSA-2026:27355
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
kpatch-patch
Fixed · RHSA-2026:33219
Red Hat Enterprise Linux 9
kernel-0:5.14.0-687.17.1.el9_8
Fixed · RHSA-2026:27789
Red Hat Enterprise Linux 9
kernel-0:5.14.0-687.17.1.el9_8
Fixed · RHSA-2026:27789
Red Hat Enterprise Linux 9
kpatch-patch
Fixed · RHSA-2026:33224
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions
kernel-0:5.14.0-284.177.1.el9_2
Fixed · RHSA-2026:27705
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions
kernel-rt-0:5.14.0-284.177.1.rt14.462.el9_2
Fixed · RHSA-2026:27706
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions
kpatch-patch
Fixed · RHSA-2026:33221
Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions
kernel-0:5.14.0-427.134.1.el9_4
Fixed · RHSA-2026:27713
Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions
kpatch-patch
Fixed · RHSA-2026:33222
Red Hat Enterprise Linux 9.6 Extended Update Support
kernel-0:5.14.0-570.123.1.el9_6
Fixed · RHSA-2026:27708
Red Hat Enterprise Linux 9.6 Extended Update Support
kpatch-patch
Fixed · RHSA-2026:33223
Red Hat OpenShift Container Platform 4.12
rhcos-412.86.202606251120-0
Fixed · RHSA-2026:34048
Red Hat OpenShift Container Platform 4.13
rhcos-413.92.202607141229-0
Fixed · RHSA-2026:40021
Red Hat OpenShift Container Platform 4.14
rhcos-414.92.202606231112-0
Fixed · RHSA-2026:28887
Red Hat OpenShift Container Platform 4.15
rhcos-415.92.202606200237-0
Fixed · RHSA-2026:28962
Red Hat OpenShift Container Platform 4.16
rhcos-416.94.202606230218-0
Fixed · RHSA-2026:29080
Red Hat OpenShift Container Platform 4.17
rhcos-417.94.202606250942-0
Fixed · RHSA-2026:34098
Red Hat OpenShift Container Platform 4.18
rhcos-418.94.202606221349-0
Fixed · RHSA-2026:29856
Red Hat OpenShift Container Platform 4.19
rhcos-4.19.9.6.202606241344-0
Fixed · RHSA-2026:29863
Red Hat OpenShift Container Platform 4.20
rhcos-4.20.9.6.202606241928-0
Fixed · RHSA-2026:29799
Red Hat OpenShift Container Platform 4.21
rhcos-4.21.9.6.202606241859-0
Fixed · RHSA-2026:29833
Red Hat OpenShift Container Platform 4.22
rhcos-4.22.9.8.202606230855-0
Fixed · RHSA-2026:29794
Red Hat Enterprise Linux 10
libkrun
Not affected
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-8
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| NVIDIA for RHEL 10 | kernel-0:6.12.0-212.11.el10nv | Fixed | RHSA-2026:27709 |
| NVIDIA for RHEL 10 | kernel-0:6.12.0-231.13.el10nv | Fixed | RHSA-2026:33666 |
| Red Hat Enterprise Linux 10 | kernel-0:6.12.0-211.26.1.el10_2 | Fixed | RHSA-2026:27288 |
| Red Hat Enterprise Linux 10 | kpatch-patch | Fixed | RHSA-2026:33225 |
| Red Hat Enterprise Linux 10.0 Extended Update Support | kernel-0:6.12.0-55.82.1.el10_0 | Fixed | RHSA-2026:27731 |
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-553.136.1.el8_10 | Fixed | RHSA-2026:27353 |
| Red Hat Enterprise Linux 8 | kernel-rt-0:4.18.0-553.136.1.rt7.477.el8_10 | Fixed | RHSA-2026:27354 |
| Red Hat Enterprise Linux 8 | kpatch-patch | Fixed | RHSA-2026:33220 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | kernel-0:4.18.0-305.195.1.el8_4 | Fixed | RHSA-2026:27707 |
| Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | kernel-0:4.18.0-305.195.1.el8_4 | Fixed | RHSA-2026:27707 |
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | kernel-0:4.18.0-372.197.1.el8_6 | Fixed | RHSA-2026:27704 |
| Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On | kernel-0:4.18.0-372.197.1.el8_6 | Fixed | RHSA-2026:27704 |
| Red Hat Enterprise Linux 8.8 Telecommunications Update Service | kernel-0:4.18.0-477.148.1.el8_8 | Fixed | RHSA-2026:27355 |
| Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | kernel-0:4.18.0-477.148.1.el8_8 | Fixed | RHSA-2026:27355 |
| Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | kpatch-patch | Fixed | RHSA-2026:33219 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-687.17.1.el9_8 | Fixed | RHSA-2026:27789 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-687.17.1.el9_8 | Fixed | RHSA-2026:27789 |
| Red Hat Enterprise Linux 9 | kpatch-patch | Fixed | RHSA-2026:33224 |
| Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | kernel-0:5.14.0-284.177.1.el9_2 | Fixed | RHSA-2026:27705 |
| Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | kernel-rt-0:5.14.0-284.177.1.rt14.462.el9_2 | Fixed | RHSA-2026:27706 |
| Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | kpatch-patch | Fixed | RHSA-2026:33221 |
| Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions | kernel-0:5.14.0-427.134.1.el9_4 | Fixed | RHSA-2026:27713 |
| Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions | kpatch-patch | Fixed | RHSA-2026:33222 |
| Red Hat Enterprise Linux 9.6 Extended Update Support | kernel-0:5.14.0-570.123.1.el9_6 | Fixed | RHSA-2026:27708 |
| Red Hat Enterprise Linux 9.6 Extended Update Support | kpatch-patch | Fixed | RHSA-2026:33223 |
| Red Hat OpenShift Container Platform 4.12 | rhcos-412.86.202606251120-0 | Fixed | RHSA-2026:34048 |
| Red Hat OpenShift Container Platform 4.13 | rhcos-413.92.202607141229-0 | Fixed | RHSA-2026:40021 |
| Red Hat OpenShift Container Platform 4.14 | rhcos-414.92.202606231112-0 | Fixed | RHSA-2026:28887 |
| Red Hat OpenShift Container Platform 4.15 | rhcos-415.92.202606200237-0 | Fixed | RHSA-2026:28962 |
| Red Hat OpenShift Container Platform 4.16 | rhcos-416.94.202606230218-0 | Fixed | RHSA-2026:29080 |
| Red Hat OpenShift Container Platform 4.17 | rhcos-417.94.202606250942-0 | Fixed | RHSA-2026:34098 |
| Red Hat OpenShift Container Platform 4.18 | rhcos-418.94.202606221349-0 | Fixed | RHSA-2026:29856 |
| Red Hat OpenShift Container Platform 4.19 | rhcos-4.19.9.6.202606241344-0 | Fixed | RHSA-2026:29863 |
| Red Hat OpenShift Container Platform 4.20 | rhcos-4.20.9.6.202606241928-0 | Fixed | RHSA-2026:29799 |
| Red Hat OpenShift Container Platform 4.21 | rhcos-4.21.9.6.202606241859-0 | Fixed | RHSA-2026:29833 |
| Red Hat OpenShift Container Platform 4.22 | rhcos-4.22.9.8.202606230855-0 | Fixed | RHSA-2026:29794 |
| Red Hat Enterprise Linux 10 | libkrun | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-8 | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat rates this flaw as Important severity. This vulnerability is in the kernel's traffic control (tc) pedit action, which requires CAP_NET_ADMIN capability to configure. By default in Red Hat Enterprise Linux, this limits exploitation to the root user or processes explicitly granted network administration capabilities. However, in some circumstances unprivileged users may obtain CAP_NET_ADMIN within user namespaces. Successful exploitation could lead to arbitrary code execution in kernel context or a system crash. Red Hat Enterprise Linux 7 and earlier are not affected. Within OpenShift Container Platform, the vulnerable module is not loaded by default, reducing the severity to Low.
Red Hat mitigation
To mitigate this vulnerability, prevent the 'act_pedit' kernel module from loading. Create a file `/etc/modprobe.d/disable-act_pedit.conf` with the following content: `install act_pedit /bin/true` Then, regenerate the initramfs and reboot the system for the changes to take effect. This may impact network traffic control functionality that relies on the pedit action.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
1 other source (Red Hat) ▾
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
PoCAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Jun 29, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
Jun–Oct 2026- EPSS v5
Percentile over time
- EPSS v5
Table of values (2 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.20% (0.00202) | 9.15th | v5 (v2026.06.15) |
| Jun 16, 2026 | 0.14% (0.00140) | 3.62th | v5 (v2026.06.15) |
References (47)
- https://access.redhat.com/errata/RHSA-2026:27288 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:27353 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:27354 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:27355 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:27704 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:27705 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:27706 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:27707 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:27708 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:27709 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:27713 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:27731 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:27789 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:28887 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:28962 Issue Tracking
- https://access.redhat.com/errata/RHSA-2026:29080 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:29794 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:29799 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:29833 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:29856 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:29863 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:33219 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:33220 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:33221 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:33222 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:33223 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:33224 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:33225 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:33666 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:34048
- https://access.redhat.com/errata/RHSA-2026:34098
- https://access.redhat.com/errata/RHSA-2026:40021
- https://access.redhat.com/security/cve/CVE-2026-46331 Third Party AdvisoryVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2479492 Third Party AdvisoryIssue Tracking
- https://git.kernel.org/stable/c/2bec122b9fb91507a758ab5e3e5c4fbe7cb3f61b Patch
- https://git.kernel.org/stable/c/3dee9d0c198faeb95d052c1b94c2958751a28512 Patch
- https://git.kernel.org/stable/c/544d857b42a1734b923040e13aa61a6fd4746cf2 Patch
- https://git.kernel.org/stable/c/899ee91156e57784090c5565e4f31bd7dbffbc5a Patch
- https://git.kernel.org/stable/c/a071e057518decc5e3bec89855758f5f8786f2c5 Patch
- https://git.kernel.org/stable/c/b198ed4e52580a7238c7c7082f03906f8b310313 Patch
- https://git.kernel.org/stable/c/b685d6ef6f07a3b5ce814565a25f39f2157538a5 Patch
- https://git.kernel.org/stable/c/d5d01d35a5a7d36f7cb679b67d9cbdd5205672dc Patch
- https://github.com/sgkdev/packet_edit_meme/tree/main exploitThird Party Advisory
- https://lore.kernel.org/netdev/20260516162825.1480113-1-rollkingzzc@gmail.com/
- https://nvd.nist.gov/vuln/detail/CVE-2026-46331
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-46331.json Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-46331
Change history (0)
No recorded changes yet.