Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-46323

32
FAUCET Score

In the Linux kernel, the following vulnerability has been resolved: net: gro: don't merge zcopy skbs skb_gro_receive() can currently copy frags between the source and GRO skb, without checking the zerocopy status, and in particular the SKBFL_MANAGED_FRAG_REFS flag. When SKBFL_MANAGED_FRAG_REFS is set, the skb doesn't hold a reference on the pages in shinfo->frags. Appending those frags to another skb's frags without fixing up the page refcount can lead to UAF. When either the last skb in the GRO chain (the one we would append frags to) or the source skb is zerocopy, don't merge the skbs.

First published: Jun 9, 2026Last modified: Jun 19, 2026

Impacted Technologies

VendorProductVersion(s)CPE
>= 6.0, < 6.1.176CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 6.2, < 6.6.142CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 6.7, < 6.12.92CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 6.13, < 6.18.34CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 6.19, < 7.0.11CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.14%
Probability of exploitation in next 30 days
EPSS Percentile
3.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0014 is in the 16th percentile among its peer group of 17,061 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (8)

microsoftpatch availablevia msrc
Product: 21443-17084Fixed in: 6.6.142.1-1
microsoftpatch availablevia msrc
Product: azl3 kernel 6.6.141.1-1 on Azure Linux 3.0Fixed in: 6.6.143.1-1
microsoftpatch availablevia msrc
Product: 21443-17084Fixed in: 6.6.143.1-1
ubuntupatch availablevia ubuntu_usn
Product: linux-lowlatency-hwe-6.8 (jammy)Fixed in: 6.8.0-134.134.1~22.04.1
ubuntupatch availablevia ubuntu_usn
Product: linux-hwe-7.0 (noble)Fixed in: 7.0.0-28.28~24.04.1
ubuntupatch availablevia ubuntu_usn
Product: linux-lowlatency (noble)Fixed in: 6.8.0-134.134.1
ubuntupatch availablevia ubuntu_usn
Product: linux-oem-7.0 (resolute)Fixed in: 7.0.0-1008.8
ubuntupatch availablevia ubuntu_usn
Product: linux-xilinx (noble)Fixed in: 6.8.0-1032.33

Vendor Advisories (5)

ubuntuUSN-8569-1

Linux kernel (HWE) vulnerabilities

Jul 20, 2026
ubuntuUSN-8499-1

Linux kernel (Xilinx) vulnerabilities

Jul 2, 2026
ubuntuUSN-8497-1

Linux kernel (Low Latency) vulnerabilities

Jul 2, 2026
ubuntuUSN-8489-1

Linux kernel (OEM) vulnerabilities

Jul 1, 2026
microsoft2026-Jun/CVE-2026-46323Moderate

net: gro: don't merge zcopy skbs

Jun 9, 2026

References

access.redhat.com / errata/RHSA-2026:27708
Third Party Advisory
access.redhat.com / errata/RHSA-2026:27731
Third Party Advisory
access.redhat.com / errata/RHSA-2026:27735
Third Party Advisory
access.redhat.com / errata/RHSA-2026:36018
Third Party Advisory
access.redhat.com / errata/RHSA-2026:44270
access.redhat.com / security/cve/CVE-2026-46323
Third Party Advisory
bugzilla.redhat.com / show_bug.cgi
Third Party Advisory
security.access.redhat.com / data/csaf/v2/vex/2026/cve-2026-46323.json
Third Party Advisory
git.kernel.org / stable/c/1f9c828556416fbe3f49386708ce999fc4d4da06
Patch
git.kernel.org / stable/c/3c6cc9f2ca65b6dd61b1af75452dc0e1cd0aad8d
Patch
git.kernel.org / stable/c/44bea2032af0425e4ce6d26a8af0ede79db49ec1
Patch
git.kernel.org / stable/c/479084ae0e1d9cb7929cb4298d35623de189f80a
Patch
git.kernel.org / stable/c/4db79a322db8c97f7b73b8a347395ef4d685eb40
Patch
git.kernel.org / stable/c/e334cbf3388fd9334503a778a82d9e9f14dd2f71
Patch