{
    "id": "CVE-2026-46300",
    "published": "2026-05-23 12:17:02",
    "last_modified": "2026-09-08 09:18:09",
    "cvss_score": "7.8",
    "cvss_severity": "HIGH",
    "cvss_version": "3.1",
    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
    "cwe": "CWE-787",
    "description": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: skbuff: preserve shared-frag marker during coalescing\n\nskb_try_coalesce() can attach paged frags from @from to @to.  If @from\nhas SKBFL_SHARED_FRAG set, the resulting @to skb can contain the same\nexternally-owned or page-cache-backed frags, but the shared-frag marker\nis currently lost.\n\nThat breaks the invariant relied on by later in-place writers.  In\nparticular, ESP input checks skb_has_shared_frag() before deciding\nwhether an uncloned nonlinear skb can skip skb_cow_data().  If TCP\nreceive coalescing has moved shared frags into an unmarked skb, ESP can\nsee skb_has_shared_frag() as false and decrypt in place over page-cache\nbacked frags.\n\nPropagate SKBFL_SHARED_FRAG when skb_try_coalesce() transfers paged\nfrags.  The tailroom copy path does not need the marker because it copies\nbytes into @to's linear data rather than transferring frag descriptors.",
    "epss_score": "0.02425",
    "epss_percentile": "0.83727",
    "kev": 0,
    "kev_due": null,
    "has_exploit": 1,
    "updated_at": "2026-10-09 18:17:56",
    "priority": {
        "rank": 2,
        "label": "Patch early",
        "why": "A public exploit exists."
    },
    "products": [
        {
            "vendor": "linux",
            "product": "linux_kernel"
        }
    ],
    "kev_detail": null,
    "exploits": [
        {
            "source": "exploit-db",
            "ref_id": "52591",
            "title": "Linux Kernel -  Local Privilege Escalation",
            "date": "2026-05-29",
            "url": "https://www.exploit-db.com/exploits/52591"
        }
    ],
    "refs_list": [
        "https://git.kernel.org/stable/c/2f2b16022a2e10ca7bccfb98db5ed2ec0f72641c",
        "https://git.kernel.org/stable/c/3599e6b3cc1ada96883d496a50a210d3afbb6987",
        "https://git.kernel.org/stable/c/3884358a9286b17f389a72b1426fc4547c23c111",
        "https://git.kernel.org/stable/c/3bd9e113d50034db99d7ef69fd8e5242d15e414a",
        "https://git.kernel.org/stable/c/760e1addc27ba1a7beb4a0a7e8b3e9ec49e7a34e",
        "https://git.kernel.org/stable/c/78bf6b6bb19541d19fbda6242e7cfe2c682763c0",
        "https://git.kernel.org/stable/c/9d3e5fd19fe1063bf607219e8562fbd567b8e8d5",
        "https://git.kernel.org/stable/c/f84eca5817390257cef78013d0112481c503b4a3",
        "http://www.openwall.com/lists/oss-security/2026/05/13/5",
        "http://www.openwall.com/lists/oss-security/2026/05/21/11",
        "http://www.openwall.com/lists/oss-security/2026/05/21/12",
        "http://www.openwall.com/lists/oss-security/2026/05/21/13",
        "https://access.redhat.com/errata/RHBA-2026:20032",
        "https://access.redhat.com/errata/RHSA-2026:19521",
        "https://access.redhat.com/errata/RHSA-2026:19540",
        "https://access.redhat.com/errata/RHSA-2026:19568",
        "https://access.redhat.com/errata/RHSA-2026:19569",
        "https://access.redhat.com/errata/RHSA-2026:19664",
        "https://access.redhat.com/errata/RHSA-2026:19666",
        "https://access.redhat.com/errata/RHSA-2026:19705",
        "https://access.redhat.com/errata/RHSA-2026:19711",
        "https://access.redhat.com/errata/RHSA-2026:19875",
        "https://access.redhat.com/errata/RHSA-2026:20051",
        "https://access.redhat.com/errata/RHSA-2026:20054",
        "https://access.redhat.com/errata/RHSA-2026:20087"
    ]
}