CVE-2026-46321
tun: free page on short-frame rejection in tun_xdp_one()
Description
In the Linux kernel, the following vulnerability has been resolved: tun: free page on short-frame rejection in tun_xdp_one() tun_xdp_one() returns -EINVAL on a frame shorter than ETH_HLEN without freeing the page that vhost_net_build_xdp() allocated for it. tun_sendmsg() discards that -EINVAL and still returns total_len, so vhost_tx_batch() takes the success path and never frees the page; each short frame in a batch leaks one page-frag chunk. A local process that can open /dev/net/tun and /dev/vhost-net can hit this path: it attaches a tun/tap device as the vhost-net backend and feeds TX descriptors whose length minus the virtio-net header is below ETH_HLEN. Each kick leaks the page-frag chunks for that batch, and a tight submission loop exhausts host memory and triggers an OOM panic. Free the page before returning -EINVAL, matching the XDP-program error path in the same function.
INFO
Published Date :
June 9, 2026, 1:16 p.m.
Last Modified :
July 23, 2026, 8:10 a.m.
Remotely Exploit :
No
Source :
416baaa9-dc9f-4396-8d5f-8c081fb06d67
CVSS Scores
| Score | Version | Severity | Vector | Exploitability Score | Impact Score | Source |
|---|---|---|---|---|---|---|
| CVSS 3.1 | HIGH | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
Solution
- Free the page before returning -EINVAL in tun_xdp_one().
- Ensure page is freed on short frame rejection.
- Apply the provided patch to the Linux kernel.
Public PoC/Exploit Available at Github
CVE-2026-46321 has a 1 public
PoC/Exploit available at Github.
Go to the Public Exploits tab to see the list.
References to Advisories, Solutions, and Tools
Here, you will find a curated list of external links that provide in-depth
information, practical solutions, and valuable tools related to
CVE-2026-46321.
CWE - Common Weakness Enumeration
While CVE identifies
specific instances of vulnerabilities, CWE categorizes the common flaws or
weaknesses that can lead to vulnerabilities. CVE-2026-46321 is
associated with the following CWEs:
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Attack Pattern Enumeration and Classification
(CAPEC)
stores attack patterns, which are descriptions of the common attributes and
approaches employed by adversaries to exploit the CVE-2026-46321
weaknesses.
We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).
None
Python
Results are limited to the first 15 repositories due to potential performance issues.
The following list is the news that have been mention
CVE-2026-46321 vulnerability anywhere in the article.
The following table lists the changes that have been made to the
CVE-2026-46321 vulnerability over time.
Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.
-
CVE Translated by [email protected]
Jul. 23, 2026
Action Type Old Value New Value Added Translation Title: el kernel de Linux, Description: En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta: tun: liberar página en el rechazo de tramas cortas en tun_xdp_one() tun_xdp_one() devuelve -EINVAL en una trama más corta que ETH_HLEN sin liberar la página que vhost_net_build_xdp() asignó para ella. tun_sendmsg() descarta ese -EINVAL y aún devuelve total_len, por lo que vhost_tx_batch() toma la ruta de éxito y nunca libera la página; cada trama corta en un lote filtra un chunk de fragmento de página. Un proceso local que puede abrir /dev/net/tun y /dev/vhost-net puede alcanzar esta ruta: adjunta un dispositivo tun/tap como el backend de vhost-net y alimenta descriptores TX cuya longitud menos el encabezado virtio-net está por debajo de ETH_HLEN. Cada kick filtra los chunks de fragmentos de página para ese lote, y un bucle de envío ajustado agota la memoria del host y desencadena un pánico OOM. Liberar la página antes de devolver -EINVAL, coincidiendo con la ruta de error del programa XDP en la misma función. -
Initial Analysis by [email protected]
Jul. 08, 2026
Action Type Old Value New Value Added CWE NVD-CWE-noinfo Added CPE Configuration OR *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 5.4.281 up to (excluding) 5.5 *cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:* *cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:* *cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:* *cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:* *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.13 up to (excluding) 6.18.35 *cpe:2.3:o:linux:linux_kernel:7.1:rc5:*:*:*:*:*:* *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.19 up to (excluding) 7.0.12 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 5.10.223 up to (excluding) 5.10.259 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 5.15.164 up to (excluding) 5.15.210 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.1.102 up to (excluding) 6.1.176 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.10.2 up to (excluding) 6.12.93 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.6.43 up to (excluding) 6.6.143 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.9.12 up to (excluding) 6.10 Added Reference Type kernel.org: https://git.kernel.org/stable/c/0a6f46a9332ad6958992d64d3b3a81a80b2ca940 Types: Patch Added Reference Type kernel.org: https://git.kernel.org/stable/c/0e8211fcf9426f5adddf32516ba0f400ceb9544d Types: Patch Added Reference Type kernel.org: https://git.kernel.org/stable/c/37a1c268c2c8090bf4dc552d732bd23ba36f8eb0 Types: Patch Added Reference Type kernel.org: https://git.kernel.org/stable/c/5b34f9e4fe2f203724a6e893d6df0316b9670057 Types: Patch Added Reference Type kernel.org: https://git.kernel.org/stable/c/69863ff2720a0e9871f1a5710f2a33a94217fee0 Types: Patch Added Reference Type kernel.org: https://git.kernel.org/stable/c/98c67be9eb9de72465a071949e84a3cdb8fab5a3 Types: Patch Added Reference Type kernel.org: https://git.kernel.org/stable/c/e915445942af6dcea628bf66d6241641201a0c41 Types: Patch Added Reference Type kernel.org: https://git.kernel.org/stable/c/f4feb1e20058e407cb00f45aff47f5b7e19a6bbf Types: Patch -
CVE Modified by 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Jun. 19, 2026
Action Type Old Value New Value Added Reference https://git.kernel.org/stable/c/0a6f46a9332ad6958992d64d3b3a81a80b2ca940 Added Reference https://git.kernel.org/stable/c/0e8211fcf9426f5adddf32516ba0f400ceb9544d Added Reference https://git.kernel.org/stable/c/5b34f9e4fe2f203724a6e893d6df0316b9670057 Added Reference https://git.kernel.org/stable/c/e915445942af6dcea628bf66d6241641201a0c41 Changed Affected [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '049584807f1d797fc3078b68035450a9769eb5c3', 'lessThan': '69863ff2720a0e9871f1a5710f2a33a94217fee0', 'versionType': 'git'}, {'status': 'affected', 'version': '049584807f1d797fc3078b68035450a9769eb5c3', 'lessThan': '37a1c268c2c8090bf4dc552d732bd23ba36f8eb0', 'versionType': 'git'}, {'status': 'affected', 'version': '049584807f1d797fc3078b68035450a9769eb5c3', 'lessThan': '98c67be9eb9de72465a071949e84a3cdb8fab5a3', 'versionType': 'git'}, {'status': 'affected', 'version': '049584807f1d797fc3078b68035450a9769eb5c3', 'lessThan': 'f4feb1e20058e407cb00f45aff47f5b7e19a6bbf', 'versionType': 'git'}, {'status': 'affected', 'version': '32b0aaba5dbc85816898167d9b5d45a22eae82e9', 'versionType': 'git'}, {'status': 'affected', 'version': '6100e0237204890269e3f934acfc50d35fd6f319', 'versionType': 'git'}, {'status': 'affected', 'version': '589382f50b4a5d90d16d8bc9dcbc0e927a3e39b2', 'versionType': 'git'}, {'status': 'affected', 'version': 'ad6b3f622ccfb4bfedfa53b6ebd91c3d1d04f146', 'versionType': 'git'}, {'status': 'affected', 'version': 'd5ad89b7d01ed4e66fd04734fc63d6e78536692a', 'versionType': 'git'}, {'status': 'affected', 'version': 'a9d1c27e2ee3b0ea5d40c105d6e728fc114470bb', 'versionType': 'git'}, {'status': 'affected', 'version': '8418f55302fa1d2eeb73e16e345167e545c598a5', 'versionType': 'git'}, {'status': 'affected', 'version': '5.4.281', 'lessThan': '5.5', 'versionType': 'semver'}, {'status': 'affected', 'version': '5.10.223', 'lessThan': '5.11', 'versionType': 'semver'}, {'status': 'affected', 'version': '5.15.164', 'lessThan': '5.16', 'versionType': 'semver'}, {'status': 'affected', 'version': '6.1.102', 'lessThan': '6.2', 'versionType': 'semver'}, {'status': 'affected', 'version': '6.6.43', 'lessThan': '6.7', 'versionType': 'semver'}, {'status': 'affected', 'version': '6.9.12', 'lessThan': '6.10', 'versionType': 'semver'}, {'status': 'affected', 'version': '6.10.2', 'lessThan': '6.11', 'versionType': 'semver'}], 'programFiles': ['drivers/net/tun.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '6.11'}, {'status': 'unaffected', 'version': '0', 'lessThan': '6.11', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '6.12.93', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.35', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.0.12', 'versionType': 'semver', 'lessThanOrEqual': '7.0.*'}, {'status': 'unaffected', 'version': '7.1', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['drivers/net/tun.c'], 'defaultStatus': 'affected'}] [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '6100e0237204890269e3f934acfc50d35fd6f319', 'lessThan': '0a6f46a9332ad6958992d64d3b3a81a80b2ca940', 'versionType': 'git'}, {'status': 'affected', 'version': '589382f50b4a5d90d16d8bc9dcbc0e927a3e39b2', 'lessThan': '0e8211fcf9426f5adddf32516ba0f400ceb9544d', 'versionType': 'git'}, {'status': 'affected', 'version': 'ad6b3f622ccfb4bfedfa53b6ebd91c3d1d04f146', 'lessThan': 'e915445942af6dcea628bf66d6241641201a0c41', 'versionType': 'git'}, {'status': 'affected', 'version': 'd5ad89b7d01ed4e66fd04734fc63d6e78536692a', 'lessThan': '5b34f9e4fe2f203724a6e893d6df0316b9670057', 'versionType': 'git'}, {'status': 'affected', 'version': '049584807f1d797fc3078b68035450a9769eb5c3', 'lessThan': '69863ff2720a0e9871f1a5710f2a33a94217fee0', 'versionType': 'git'}, {'status': 'affected', 'version': '049584807f1d797fc3078b68035450a9769eb5c3', 'lessThan': '37a1c268c2c8090bf4dc552d732bd23ba36f8eb0', 'versionType': 'git'}, {'status': 'affected', 'version': '049584807f1d797fc3078b68035450a9769eb5c3', 'lessThan': '98c67be9eb9de72465a071949e84a3cdb8fab5a3', 'versionType': 'git'}, {'status': 'affected', 'version': '049584807f1d797fc3078b68035450a9769eb5c3', 'lessThan': 'f4feb1e20058e407cb00f45aff47f5b7e19a6bbf', 'versionType': 'git'}, {'status': 'affected', 'version': '32b0aaba5dbc85816898167d9b5d45a22eae82e9', 'versionType': 'git'}, {'status': 'affected', 'version': 'a9d1c27e2ee3b0ea5d40c105d6e728fc114470bb', 'versionType': 'git'}, {'status': 'affected', 'version': '8418f55302fa1d2eeb73e16e345167e545c598a5', 'versionType': 'git'}, {'status': 'affected', 'version': '5.10.223', 'lessThan': '5.10.259', 'versionType': 'semver'}, {'status': 'affected', 'version': '5.15.164', 'lessThan': '5.15.210', 'versionType': 'semver'}, {'status': 'affected', 'version': '6.1.102', 'lessThan': '6.1.176', 'versionType': 'semver'}, {'status': 'affected', 'version': '6.6.43', 'lessThan': '6.6.143', 'versionType': 'semver'}, {'status': 'affected', 'version': '5.4.281', 'lessThan': '5.5', 'versionType': 'semver'}, {'status': 'affected', 'version': '6.9.12', 'lessThan': '6.10', 'versionType': 'semver'}, {'status': 'affected', 'version': '6.10.2', 'lessThan': '6.11', 'versionType': 'semver'}], 'programFiles': ['drivers/net/tun.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '6.11'}, {'status': 'unaffected', 'version': '0', 'lessThan': '6.11', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '5.10.259', 'versionType': 'semver', 'lessThanOrEqual': '5.10.*'}, {'status': 'unaffected', 'version': '5.15.210', 'versionType': 'semver', 'lessThanOrEqual': '5.15.*'}, {'status': 'unaffected', 'version': '6.1.176', 'versionType': 'semver', 'lessThanOrEqual': '6.1.*'}, {'status': 'unaffected', 'version': '6.6.143', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.93', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.35', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.0.12', 'versionType': 'semver', 'lessThanOrEqual': '7.0.*'}, {'status': 'unaffected', 'version': '7.1', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['drivers/net/tun.c'], 'defaultStatus': 'affected'}] -
CVE Modified by 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Jun. 17, 2026
Action Type Old Value New Value Added Affected [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '049584807f1d797fc3078b68035450a9769eb5c3', 'lessThan': '69863ff2720a0e9871f1a5710f2a33a94217fee0', 'versionType': 'git'}, {'status': 'affected', 'version': '049584807f1d797fc3078b68035450a9769eb5c3', 'lessThan': '37a1c268c2c8090bf4dc552d732bd23ba36f8eb0', 'versionType': 'git'}, {'status': 'affected', 'version': '049584807f1d797fc3078b68035450a9769eb5c3', 'lessThan': '98c67be9eb9de72465a071949e84a3cdb8fab5a3', 'versionType': 'git'}, {'status': 'affected', 'version': '049584807f1d797fc3078b68035450a9769eb5c3', 'lessThan': 'f4feb1e20058e407cb00f45aff47f5b7e19a6bbf', 'versionType': 'git'}, {'status': 'affected', 'version': '32b0aaba5dbc85816898167d9b5d45a22eae82e9', 'versionType': 'git'}, {'status': 'affected', 'version': '6100e0237204890269e3f934acfc50d35fd6f319', 'versionType': 'git'}, {'status': 'affected', 'version': '589382f50b4a5d90d16d8bc9dcbc0e927a3e39b2', 'versionType': 'git'}, {'status': 'affected', 'version': 'ad6b3f622ccfb4bfedfa53b6ebd91c3d1d04f146', 'versionType': 'git'}, {'status': 'affected', 'version': 'd5ad89b7d01ed4e66fd04734fc63d6e78536692a', 'versionType': 'git'}, {'status': 'affected', 'version': 'a9d1c27e2ee3b0ea5d40c105d6e728fc114470bb', 'versionType': 'git'}, {'status': 'affected', 'version': '8418f55302fa1d2eeb73e16e345167e545c598a5', 'versionType': 'git'}, {'status': 'affected', 'version': '5.4.281', 'lessThan': '5.5', 'versionType': 'semver'}, {'status': 'affected', 'version': '5.10.223', 'lessThan': '5.11', 'versionType': 'semver'}, {'status': 'affected', 'version': '5.15.164', 'lessThan': '5.16', 'versionType': 'semver'}, {'status': 'affected', 'version': '6.1.102', 'lessThan': '6.2', 'versionType': 'semver'}, {'status': 'affected', 'version': '6.6.43', 'lessThan': '6.7', 'versionType': 'semver'}, {'status': 'affected', 'version': '6.9.12', 'lessThan': '6.10', 'versionType': 'semver'}, {'status': 'affected', 'version': '6.10.2', 'lessThan': '6.11', 'versionType': 'semver'}], 'programFiles': ['drivers/net/tun.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '6.11'}, {'status': 'unaffected', 'version': '0', 'lessThan': '6.11', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '6.12.93', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.35', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.0.12', 'versionType': 'semver', 'lessThanOrEqual': '7.0.*'}, {'status': 'unaffected', 'version': '7.1', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['drivers/net/tun.c'], 'defaultStatus': 'affected'}] -
CVE Modified by 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Jun. 14, 2026
Action Type Old Value New Value Added CVSS V3.1 AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H -
New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Jun. 09, 2026
Action Type Old Value New Value Added Description In the Linux kernel, the following vulnerability has been resolved: tun: free page on short-frame rejection in tun_xdp_one() tun_xdp_one() returns -EINVAL on a frame shorter than ETH_HLEN without freeing the page that vhost_net_build_xdp() allocated for it. tun_sendmsg() discards that -EINVAL and still returns total_len, so vhost_tx_batch() takes the success path and never frees the page; each short frame in a batch leaks one page-frag chunk. A local process that can open /dev/net/tun and /dev/vhost-net can hit this path: it attaches a tun/tap device as the vhost-net backend and feeds TX descriptors whose length minus the virtio-net header is below ETH_HLEN. Each kick leaks the page-frag chunks for that batch, and a tight submission loop exhausts host memory and triggers an OOM panic. Free the page before returning -EINVAL, matching the XDP-program error path in the same function. Added Reference https://git.kernel.org/stable/c/37a1c268c2c8090bf4dc552d732bd23ba36f8eb0 Added Reference https://git.kernel.org/stable/c/69863ff2720a0e9871f1a5710f2a33a94217fee0 Added Reference https://git.kernel.org/stable/c/98c67be9eb9de72465a071949e84a3cdb8fab5a3 Added Reference https://git.kernel.org/stable/c/f4feb1e20058e407cb00f45aff47f5b7e19a6bbf