CVE-2026-46300
Linux Kernel28/100
exploitation likelihood
CVSS7.8
EPSS9.5%
KEVNone
In the Linux kernel, the following vulnerability has been resolved:
net: skbuff: preserve shared-frag marker during coalescing
skb_try_coalesce() can attach paged frags from @from to @to. If @from
has SKBFL_SHARED_FRAG set, the resulting @to skb can contain the same
externally-owned or page-cache-backed frags, but the shared-frag marker
is currently lost.
That breaks the invariant relied on by later in-place writers. In
particular, ESP input checks skb_has_shared_frag() before deciding
whet
EPSS 0.095 (probability of exploitation) · CVSS base 7.8 · 1 public PoC/exploit reference(s) available
Public PoC / Exploit1
Defensive review only — these references demonstrate exploitability.
References20
NVD detailPatchgit.kernel.orgPatchgit.kernel.orgPatchgit.kernel.orgPatchgit.kernel.orgPatchgit.kernel.orgPatchgit.kernel.orgPatchgit.kernel.orgPatchgit.kernel.orgMailing listopenwall.comMailing listopenwall.comMailing listopenwall.comMailing listopenwall.comReferenceaccess.redhat.comReferenceaccess.redhat.comReferenceaccess.redhat.comReferenceaccess.redhat.comReferenceaccess.redhat.comReferenceaccess.redhat.comReferenceaccess.redhat.comReferenceaccess.redhat.comwebcert-portal.siemens.comwebcert-portal.siemens.comwebsecurity.access.redhat.com
OSV.dev — affected packages
Linux/Kernelfixed in 7.0.10Mentions 1