openvswitch: only skb_tx_error() a packet we are about to drop
Published Sep 11, 2026
7.8
HIGHCVSS 3.1
EPSS 0.13%
Description
queue_userspace_packet() borrows the packet skb -- it only copies it into a private netlink message (user_skb) and does not own it; on return do_execute_actions() keeps forwarding it through the flow's remaining actions. Its error path nevertheless calls skb_tx_error(skb), which via skb_zcopy_clear() does skb_shinfo(skb)->flags &= ~SKBFL_ALL_ZEROCOPY, stripping SKBFL_SHARED_FRAG from that live skb (skb_tx_error()'s kerneldoc says "skb must be freed afterwards").
For a MSG_ZEROCOPY skb carrying page-cache frags, SKBFL_SHARED_FRAG is what makes esp_input() skb_cow_data() before in-place AEAD; once it is stripped a later local ESP-in-UDP delivery decrypts in place over pages the sender does not own -- an unprivileged page-cache write (the "Fragnesia" primitive). do_execute_actions() ignores output_userspace()'s return value, so any action after a failed USERSPACE upcall inherits the stripped skb.
Move the skb_tx_error() to the flow-miss drop path - the "default" branch of ovs_dp_process_packet()'s switch(error), before kfree_skb().
The call has been here since commit 36d5fe6a0007 ("core, nfqueue, openvswitch: Orphan frags in skb_zerocopy and handle errors") but was harmless until esp_input() began relying on SKBFL_SHARED_FRAG to gate in-place decrypt; only then did stripping it on a still-forwarded skb become a page-cache write primitive.
Affected products
-
- Version StatusaffectedConstraints-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints-
- Version
-
- Version 3.10.51StatusaffectedConstraints<3.11
- Version 3.12.40StatusaffectedConstraints<3.13
- Version
-
- Version 3.14StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<3.14
- Version 5.10.270StatusunaffectedConstraints<=5.10.*
- Version 5.15.221StatusunaffectedConstraints<=5.15.*
- Version 6.1.188StatusunaffectedConstraints<=6.1.*
- Version 6.12.109StatusunaffectedConstraints<=6.12.*
- Version 6.18.50StatusunaffectedConstraints<=6.18.*
- Version 6.6.157StatusunaffectedConstraints<=6.6.*
- Version 7.2.4StatusunaffectedConstraints<=7.2.*
- Version 7.3-rc1StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| |||||||||||||||||||||||||||||||||
| Linux | Linux | unaffected |
| |||||||||||||||||||||||||||||||||
| Linux | Linux | affected |
|
No data.
No data.
Red Hat Enterprise Linux 10
kernel
Affected
Red Hat Enterprise Linux 10
kernel-rt
Affected
Red Hat Enterprise Linux 6
kernel
Under investigation
Red Hat Enterprise Linux 7
kernel
Affected
Red Hat Enterprise Linux 7
kernel-rt
Affected
Red Hat Enterprise Linux 8
kernel
Affected
Red Hat Enterprise Linux 8
kernel-rt
Affected
Red Hat Enterprise Linux 9
kernel
Affected
Red Hat Enterprise Linux 9
kernel-rt
Affected
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-8
Affected
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-9
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel | Affected | n/a |
| Red Hat Enterprise Linux 10 | kernel-rt | Affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Under investigation | n/a |
| Red Hat Enterprise Linux 7 | kernel | Affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-8 | Affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-9 | Affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (14)
- https://access.redhat.com/security/cve/CVE-2026-89487 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2532517 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-76393 Advisory
- https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-89487.mbox
- https://git.kernel.org/stable/c/0dbc2398fca3bb33eda963849f865ddb1b3aa05e
- https://git.kernel.org/stable/c/4477222e2916a18e273edc139c955ade6bbb7a69
- https://git.kernel.org/stable/c/48db11e115d1b232edc5591604adc6eda95cd545
- https://git.kernel.org/stable/c/4d5c460ef8754be1d43b16dbf02695b008b207d6
- https://git.kernel.org/stable/c/5d85eef222cfd28e73deed7402c100229e8b9e6e
- https://git.kernel.org/stable/c/5de5d554141a15b3f1f5c978fd9f7f4fd6d0600a
- https://git.kernel.org/stable/c/6767d70cf46f65807a6a4c4406a518e6c12e36ae
- https://git.kernel.org/stable/c/e41a59fc056f63a7a1f42788913c53cc48d744aa
- https://nvd.nist.gov/vuln/detail/CVE-2026-89487
- https://www.cve.org/CVERecord?id=CVE-2026-89487
Change history (0)
No recorded changes yet.