7.1
HIGH CVSS 3.1
CVE-2026-46321
tun: free page on short-frame rejection in tun_xdp_one()
Description

In the Linux kernel, the following vulnerability has been resolved: tun: free page on short-frame rejection in tun_xdp_one() tun_xdp_one() returns -EINVAL on a frame shorter than ETH_HLEN without freeing the page that vhost_net_build_xdp() allocated for it. tun_sendmsg() discards that -EINVAL and still returns total_len, so vhost_tx_batch() takes the success path and never frees the page; each short frame in a batch leaks one page-frag chunk. A local process that can open /dev/net/tun and /dev/vhost-net can hit this path: it attaches a tun/tap device as the vhost-net backend and feeds TX descriptors whose length minus the virtio-net header is below ETH_HLEN. Each kick leaks the page-frag chunks for that batch, and a tight submission loop exhausts host memory and triggers an OOM panic. Free the page before returning -EINVAL, matching the XDP-program error path in the same function.

INFO

Published Date :

June 9, 2026, 1:16 p.m.

Last Modified :

July 23, 2026, 8:10 a.m.

Remotely Exploit :

No

Source :

416baaa9-dc9f-4396-8d5f-8c081fb06d67
Affected Products

The following products are affected by CVE-2026-46321 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

ID Vendor Product Action
1 Linux linux_kernel
CVSS Scores
The Common Vulnerability Scoring System is a standardized framework for assessing the severity of vulnerabilities in software and systems. We collect and displays CVSS scores from various sources for each CVE.
Score Version Severity Vector Exploitability Score Impact Score Source
CVSS 3.1 HIGH 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Solution
Free allocated pages when short frames are rejected to prevent memory leaks and OOM panics.
  • Free the page before returning -EINVAL in tun_xdp_one().
  • Ensure page is freed on short frame rejection.
  • Apply the provided patch to the Linux kernel.
Public PoC/Exploit Available at Github

CVE-2026-46321 has a 1 public PoC/Exploit available at Github. Go to the Public Exploits tab to see the list.

CWE - Common Weakness Enumeration

While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2026-46321 is associated with the following CWEs:

Common Attack Pattern Enumeration and Classification (CAPEC)

Common Attack Pattern Enumeration and Classification (CAPEC) stores attack patterns, which are descriptions of the common attributes and approaches employed by adversaries to exploit the CVE-2026-46321 weaknesses.

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

None

Python

Updated: 1 week, 1 day ago
0 stars 0 fork 0 watcher
Born at : July 8, 2025, 4:34 a.m. This repo has been linked 79 different CVEs too.

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2026-46321 vulnerability anywhere in the article.

The following table lists the changes that have been made to the CVE-2026-46321 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.

  • CVE Translated by [email protected]

    Jul. 23, 2026

    Action Type Old Value New Value
    Added Translation Title: el kernel de Linux, Description: En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta: tun: liberar página en el rechazo de tramas cortas en tun_xdp_one() tun_xdp_one() devuelve -EINVAL en una trama más corta que ETH_HLEN sin liberar la página que vhost_net_build_xdp() asignó para ella. tun_sendmsg() descarta ese -EINVAL y aún devuelve total_len, por lo que vhost_tx_batch() toma la ruta de éxito y nunca libera la página; cada trama corta en un lote filtra un chunk de fragmento de página. Un proceso local que puede abrir /dev/net/tun y /dev/vhost-net puede alcanzar esta ruta: adjunta un dispositivo tun/tap como el backend de vhost-net y alimenta descriptores TX cuya longitud menos el encabezado virtio-net está por debajo de ETH_HLEN. Cada kick filtra los chunks de fragmentos de página para ese lote, y un bucle de envío ajustado agota la memoria del host y desencadena un pánico OOM. Liberar la página antes de devolver -EINVAL, coincidiendo con la ruta de error del programa XDP en la misma función.
  • Initial Analysis by [email protected]

    Jul. 08, 2026

    Action Type Old Value New Value
    Added CWE NVD-CWE-noinfo
    Added CPE Configuration OR *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 5.4.281 up to (excluding) 5.5 *cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:* *cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:* *cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:* *cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:* *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.13 up to (excluding) 6.18.35 *cpe:2.3:o:linux:linux_kernel:7.1:rc5:*:*:*:*:*:* *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.19 up to (excluding) 7.0.12 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 5.10.223 up to (excluding) 5.10.259 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 5.15.164 up to (excluding) 5.15.210 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.1.102 up to (excluding) 6.1.176 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.10.2 up to (excluding) 6.12.93 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.6.43 up to (excluding) 6.6.143 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.9.12 up to (excluding) 6.10
    Added Reference Type kernel.org: https://git.kernel.org/stable/c/0a6f46a9332ad6958992d64d3b3a81a80b2ca940 Types: Patch
    Added Reference Type kernel.org: https://git.kernel.org/stable/c/0e8211fcf9426f5adddf32516ba0f400ceb9544d Types: Patch
    Added Reference Type kernel.org: https://git.kernel.org/stable/c/37a1c268c2c8090bf4dc552d732bd23ba36f8eb0 Types: Patch
    Added Reference Type kernel.org: https://git.kernel.org/stable/c/5b34f9e4fe2f203724a6e893d6df0316b9670057 Types: Patch
    Added Reference Type kernel.org: https://git.kernel.org/stable/c/69863ff2720a0e9871f1a5710f2a33a94217fee0 Types: Patch
    Added Reference Type kernel.org: https://git.kernel.org/stable/c/98c67be9eb9de72465a071949e84a3cdb8fab5a3 Types: Patch
    Added Reference Type kernel.org: https://git.kernel.org/stable/c/e915445942af6dcea628bf66d6241641201a0c41 Types: Patch
    Added Reference Type kernel.org: https://git.kernel.org/stable/c/f4feb1e20058e407cb00f45aff47f5b7e19a6bbf Types: Patch
  • CVE Modified by 416baaa9-dc9f-4396-8d5f-8c081fb06d67

    Jun. 19, 2026

    Action Type Old Value New Value
    Added Reference https://git.kernel.org/stable/c/0a6f46a9332ad6958992d64d3b3a81a80b2ca940
    Added Reference https://git.kernel.org/stable/c/0e8211fcf9426f5adddf32516ba0f400ceb9544d
    Added Reference https://git.kernel.org/stable/c/5b34f9e4fe2f203724a6e893d6df0316b9670057
    Added Reference https://git.kernel.org/stable/c/e915445942af6dcea628bf66d6241641201a0c41
    Changed Affected [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '049584807f1d797fc3078b68035450a9769eb5c3', 'lessThan': '69863ff2720a0e9871f1a5710f2a33a94217fee0', 'versionType': 'git'}, {'status': 'affected', 'version': '049584807f1d797fc3078b68035450a9769eb5c3', 'lessThan': '37a1c268c2c8090bf4dc552d732bd23ba36f8eb0', 'versionType': 'git'}, {'status': 'affected', 'version': '049584807f1d797fc3078b68035450a9769eb5c3', 'lessThan': '98c67be9eb9de72465a071949e84a3cdb8fab5a3', 'versionType': 'git'}, {'status': 'affected', 'version': '049584807f1d797fc3078b68035450a9769eb5c3', 'lessThan': 'f4feb1e20058e407cb00f45aff47f5b7e19a6bbf', 'versionType': 'git'}, {'status': 'affected', 'version': '32b0aaba5dbc85816898167d9b5d45a22eae82e9', 'versionType': 'git'}, {'status': 'affected', 'version': '6100e0237204890269e3f934acfc50d35fd6f319', 'versionType': 'git'}, {'status': 'affected', 'version': '589382f50b4a5d90d16d8bc9dcbc0e927a3e39b2', 'versionType': 'git'}, {'status': 'affected', 'version': 'ad6b3f622ccfb4bfedfa53b6ebd91c3d1d04f146', 'versionType': 'git'}, {'status': 'affected', 'version': 'd5ad89b7d01ed4e66fd04734fc63d6e78536692a', 'versionType': 'git'}, {'status': 'affected', 'version': 'a9d1c27e2ee3b0ea5d40c105d6e728fc114470bb', 'versionType': 'git'}, {'status': 'affected', 'version': '8418f55302fa1d2eeb73e16e345167e545c598a5', 'versionType': 'git'}, {'status': 'affected', 'version': '5.4.281', 'lessThan': '5.5', 'versionType': 'semver'}, {'status': 'affected', 'version': '5.10.223', 'lessThan': '5.11', 'versionType': 'semver'}, {'status': 'affected', 'version': '5.15.164', 'lessThan': '5.16', 'versionType': 'semver'}, {'status': 'affected', 'version': '6.1.102', 'lessThan': '6.2', 'versionType': 'semver'}, {'status': 'affected', 'version': '6.6.43', 'lessThan': '6.7', 'versionType': 'semver'}, {'status': 'affected', 'version': '6.9.12', 'lessThan': '6.10', 'versionType': 'semver'}, {'status': 'affected', 'version': '6.10.2', 'lessThan': '6.11', 'versionType': 'semver'}], 'programFiles': ['drivers/net/tun.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '6.11'}, {'status': 'unaffected', 'version': '0', 'lessThan': '6.11', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '6.12.93', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.35', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.0.12', 'versionType': 'semver', 'lessThanOrEqual': '7.0.*'}, {'status': 'unaffected', 'version': '7.1', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['drivers/net/tun.c'], 'defaultStatus': 'affected'}] [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '6100e0237204890269e3f934acfc50d35fd6f319', 'lessThan': '0a6f46a9332ad6958992d64d3b3a81a80b2ca940', 'versionType': 'git'}, {'status': 'affected', 'version': '589382f50b4a5d90d16d8bc9dcbc0e927a3e39b2', 'lessThan': '0e8211fcf9426f5adddf32516ba0f400ceb9544d', 'versionType': 'git'}, {'status': 'affected', 'version': 'ad6b3f622ccfb4bfedfa53b6ebd91c3d1d04f146', 'lessThan': 'e915445942af6dcea628bf66d6241641201a0c41', 'versionType': 'git'}, {'status': 'affected', 'version': 'd5ad89b7d01ed4e66fd04734fc63d6e78536692a', 'lessThan': '5b34f9e4fe2f203724a6e893d6df0316b9670057', 'versionType': 'git'}, {'status': 'affected', 'version': '049584807f1d797fc3078b68035450a9769eb5c3', 'lessThan': '69863ff2720a0e9871f1a5710f2a33a94217fee0', 'versionType': 'git'}, {'status': 'affected', 'version': '049584807f1d797fc3078b68035450a9769eb5c3', 'lessThan': '37a1c268c2c8090bf4dc552d732bd23ba36f8eb0', 'versionType': 'git'}, {'status': 'affected', 'version': '049584807f1d797fc3078b68035450a9769eb5c3', 'lessThan': '98c67be9eb9de72465a071949e84a3cdb8fab5a3', 'versionType': 'git'}, {'status': 'affected', 'version': '049584807f1d797fc3078b68035450a9769eb5c3', 'lessThan': 'f4feb1e20058e407cb00f45aff47f5b7e19a6bbf', 'versionType': 'git'}, {'status': 'affected', 'version': '32b0aaba5dbc85816898167d9b5d45a22eae82e9', 'versionType': 'git'}, {'status': 'affected', 'version': 'a9d1c27e2ee3b0ea5d40c105d6e728fc114470bb', 'versionType': 'git'}, {'status': 'affected', 'version': '8418f55302fa1d2eeb73e16e345167e545c598a5', 'versionType': 'git'}, {'status': 'affected', 'version': '5.10.223', 'lessThan': '5.10.259', 'versionType': 'semver'}, {'status': 'affected', 'version': '5.15.164', 'lessThan': '5.15.210', 'versionType': 'semver'}, {'status': 'affected', 'version': '6.1.102', 'lessThan': '6.1.176', 'versionType': 'semver'}, {'status': 'affected', 'version': '6.6.43', 'lessThan': '6.6.143', 'versionType': 'semver'}, {'status': 'affected', 'version': '5.4.281', 'lessThan': '5.5', 'versionType': 'semver'}, {'status': 'affected', 'version': '6.9.12', 'lessThan': '6.10', 'versionType': 'semver'}, {'status': 'affected', 'version': '6.10.2', 'lessThan': '6.11', 'versionType': 'semver'}], 'programFiles': ['drivers/net/tun.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '6.11'}, {'status': 'unaffected', 'version': '0', 'lessThan': '6.11', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '5.10.259', 'versionType': 'semver', 'lessThanOrEqual': '5.10.*'}, {'status': 'unaffected', 'version': '5.15.210', 'versionType': 'semver', 'lessThanOrEqual': '5.15.*'}, {'status': 'unaffected', 'version': '6.1.176', 'versionType': 'semver', 'lessThanOrEqual': '6.1.*'}, {'status': 'unaffected', 'version': '6.6.143', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.93', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.35', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.0.12', 'versionType': 'semver', 'lessThanOrEqual': '7.0.*'}, {'status': 'unaffected', 'version': '7.1', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['drivers/net/tun.c'], 'defaultStatus': 'affected'}]
  • CVE Modified by 416baaa9-dc9f-4396-8d5f-8c081fb06d67

    Jun. 17, 2026

    Action Type Old Value New Value
    Added Affected [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '049584807f1d797fc3078b68035450a9769eb5c3', 'lessThan': '69863ff2720a0e9871f1a5710f2a33a94217fee0', 'versionType': 'git'}, {'status': 'affected', 'version': '049584807f1d797fc3078b68035450a9769eb5c3', 'lessThan': '37a1c268c2c8090bf4dc552d732bd23ba36f8eb0', 'versionType': 'git'}, {'status': 'affected', 'version': '049584807f1d797fc3078b68035450a9769eb5c3', 'lessThan': '98c67be9eb9de72465a071949e84a3cdb8fab5a3', 'versionType': 'git'}, {'status': 'affected', 'version': '049584807f1d797fc3078b68035450a9769eb5c3', 'lessThan': 'f4feb1e20058e407cb00f45aff47f5b7e19a6bbf', 'versionType': 'git'}, {'status': 'affected', 'version': '32b0aaba5dbc85816898167d9b5d45a22eae82e9', 'versionType': 'git'}, {'status': 'affected', 'version': '6100e0237204890269e3f934acfc50d35fd6f319', 'versionType': 'git'}, {'status': 'affected', 'version': '589382f50b4a5d90d16d8bc9dcbc0e927a3e39b2', 'versionType': 'git'}, {'status': 'affected', 'version': 'ad6b3f622ccfb4bfedfa53b6ebd91c3d1d04f146', 'versionType': 'git'}, {'status': 'affected', 'version': 'd5ad89b7d01ed4e66fd04734fc63d6e78536692a', 'versionType': 'git'}, {'status': 'affected', 'version': 'a9d1c27e2ee3b0ea5d40c105d6e728fc114470bb', 'versionType': 'git'}, {'status': 'affected', 'version': '8418f55302fa1d2eeb73e16e345167e545c598a5', 'versionType': 'git'}, {'status': 'affected', 'version': '5.4.281', 'lessThan': '5.5', 'versionType': 'semver'}, {'status': 'affected', 'version': '5.10.223', 'lessThan': '5.11', 'versionType': 'semver'}, {'status': 'affected', 'version': '5.15.164', 'lessThan': '5.16', 'versionType': 'semver'}, {'status': 'affected', 'version': '6.1.102', 'lessThan': '6.2', 'versionType': 'semver'}, {'status': 'affected', 'version': '6.6.43', 'lessThan': '6.7', 'versionType': 'semver'}, {'status': 'affected', 'version': '6.9.12', 'lessThan': '6.10', 'versionType': 'semver'}, {'status': 'affected', 'version': '6.10.2', 'lessThan': '6.11', 'versionType': 'semver'}], 'programFiles': ['drivers/net/tun.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '6.11'}, {'status': 'unaffected', 'version': '0', 'lessThan': '6.11', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '6.12.93', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.35', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.0.12', 'versionType': 'semver', 'lessThanOrEqual': '7.0.*'}, {'status': 'unaffected', 'version': '7.1', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['drivers/net/tun.c'], 'defaultStatus': 'affected'}]
  • CVE Modified by 416baaa9-dc9f-4396-8d5f-8c081fb06d67

    Jun. 14, 2026

    Action Type Old Value New Value
    Added CVSS V3.1 AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
  • New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67

    Jun. 09, 2026

    Action Type Old Value New Value
    Added Description In the Linux kernel, the following vulnerability has been resolved: tun: free page on short-frame rejection in tun_xdp_one() tun_xdp_one() returns -EINVAL on a frame shorter than ETH_HLEN without freeing the page that vhost_net_build_xdp() allocated for it. tun_sendmsg() discards that -EINVAL and still returns total_len, so vhost_tx_batch() takes the success path and never frees the page; each short frame in a batch leaks one page-frag chunk. A local process that can open /dev/net/tun and /dev/vhost-net can hit this path: it attaches a tun/tap device as the vhost-net backend and feeds TX descriptors whose length minus the virtio-net header is below ETH_HLEN. Each kick leaks the page-frag chunks for that batch, and a tight submission loop exhausts host memory and triggers an OOM panic. Free the page before returning -EINVAL, matching the XDP-program error path in the same function.
    Added Reference https://git.kernel.org/stable/c/37a1c268c2c8090bf4dc552d732bd23ba36f8eb0
    Added Reference https://git.kernel.org/stable/c/69863ff2720a0e9871f1a5710f2a33a94217fee0
    Added Reference https://git.kernel.org/stable/c/98c67be9eb9de72465a071949e84a3cdb8fab5a3
    Added Reference https://git.kernel.org/stable/c/f4feb1e20058e407cb00f45aff47f5b7e19a6bbf
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.