# CVE-2026-46331

## Summary

- **CVE ID:** CVE-2026-46331
- **Severity:** HIGH
- **CVSS Score:** 7.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** N/A
- **Published:** Jun 16, 2026
- **Last Modified:** Sep 15, 2026

## Description

In the Linux kernel, the following vulnerability has been resolved:

net/sched: fix pedit partial COW leading to page cache corruption

tcf_pedit_act() computes the COW range for skb_ensure_writable()
once before the key loop using tcfp_off_max_hint, but the hint does
not account for the runtime header offset added by typed keys. This
can leave part of the write region un-COW'd.

Fix by moving skb_ensure_writable() inside the per-key loop where
the actual write offset is known, and add overflow checking on the
offset arithmetic. For negative offsets (e.g. Ethernet header edits
at ingress), use skb_cow() to COW the headroom instead. Guard
offset_valid() against INT_MIN, where negation is undefined.

## Affected Products

- Linux — Linux (8b796475fd7882663a870456466a4fb315cc1bd6)
- Linux — Linux (d0c38a914b0c4c21d553da801003d36979016726)
- Linux — Linux (2ec2dd7d51a9320151f275ddbb2b53260fb32ca1)
- Linux — Linux (abe35bf3be51482593076d516a680d79e5fbc8e1)
- Linux — Linux (b773640d5bb9e2acfd91e2695717af04d47aa116)
- Linux — Linux (c19cc520b3d69904e9518d401ad0df7f4702aca0)
- Linux — Linux (4.19.244)
- Linux — Linux (5.4.195)
- Linux — Linux (5.10.117)
- Linux — Linux (5.15.41)
- Linux — Linux (5.17.9)
- Linux — Linux (5.18)
- Linux — Linux (0)
- Linux — Linux (7.1)
- Linux — Linux (6.12.94)
- Linux — Linux (6.18.36)
- Linux — Linux (7.0.13)
- Linux — Linux (5.10.260)
- Linux — Linux (5.15.211)
- Linux — Linux (6.1.177)
- Linux — Linux (6.6.144)

## References

- [CNA](https://git.kernel.org/stable/c/899ee91156e57784090c5565e4f31bd7dbffbc5a)
- [CNA](https://git.kernel.org/stable/c/2bec122b9fb91507a758ab5e3e5c4fbe7cb3f61b)
- [CNA](https://git.kernel.org/stable/c/b198ed4e52580a7238c7c7082f03906f8b310313)
- [CNA](https://git.kernel.org/stable/c/3dee9d0c198faeb95d052c1b94c2958751a28512)
- [CISA-ADP](https://github.com/sgkdev/packet_edit_meme/tree/main)
- [redhat-SADP](https://access.redhat.com/security/cve/CVE-2026-46331)
- [redhat-SADP](https://bugzilla.redhat.com/show_bug.cgi?id=2479492)
- [redhat-SADP](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-46331.json)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:27709)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:27731)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:27288)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:27705)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:27713)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:27708)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:27789)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:27353)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:33220)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:27707)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:27704)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:27355)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:33219)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:33221)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:33222)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:33223)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:33224)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:27354)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:27706)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:33225)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:29833)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:33666)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:29799)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:29794)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:28887)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:29080)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:29856)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:29863)
- [CNA](https://git.kernel.org/stable/c/544d857b42a1734b923040e13aa61a6fd4746cf2)
- [CNA](https://git.kernel.org/stable/c/d5d01d35a5a7d36f7cb679b67d9cbdd5205672dc)
- [CNA](https://git.kernel.org/stable/c/a071e057518decc5e3bec89855758f5f8786f2c5)
- [CNA](https://git.kernel.org/stable/c/b685d6ef6f07a3b5ce814565a25f39f2157538a5)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:28962)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:34048)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:34098)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:40021)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.58%
- **EPSS Percentile:** 46.5

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-19._