# CVE-2026-89487

## Summary

- **CVE ID:** CVE-2026-89487
- **Severity:** HIGH
- **CVSS Score:** 7.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** N/A
- **Published:** Sep 11, 2026
- **Last Modified:** Sep 14, 2026

## Description

In the Linux kernel, the following vulnerability has been resolved:

openvswitch: only skb_tx_error() a packet we are about to drop

queue_userspace_packet() borrows the packet skb -- it only copies it into
a private netlink message (user_skb) and does not own it; on return
do_execute_actions() keeps forwarding it through the flow's remaining
actions. Its error path nevertheless calls skb_tx_error(skb), which via
skb_zcopy_clear() does skb_shinfo(skb)->flags &= ~SKBFL_ALL_ZEROCOPY,
stripping SKBFL_SHARED_FRAG from that live skb (skb_tx_error()'s kerneldoc
says "skb must be freed afterwards").

For a MSG_ZEROCOPY skb carrying page-cache frags, SKBFL_SHARED_FRAG is
what makes esp_input() skb_cow_data() before in-place AEAD; once it is
stripped a later local ESP-in-UDP delivery decrypts in place over pages
the sender does not own -- an unprivileged page-cache write (the
"Fragnesia" primitive).
do_execute_actions() ignores output_userspace()'s return value, so any
action after a failed USERSPACE upcall inherits the stripped skb.

Move the skb_tx_error() to the flow-miss drop path - the "default"
branch of ovs_dp_process_packet()'s switch(error), before kfree_skb().

The call has been here since commit 36d5fe6a0007 ("core, nfqueue,
openvswitch: Orphan frags in skb_zerocopy and handle errors") but was
harmless until esp_input() began relying on SKBFL_SHARED_FRAG to gate
in-place decrypt; only then did stripping it on a still-forwarded skb
become a page-cache write primitive.

## Affected Products

- Linux — Linux (36d5fe6a000790f56039afe26834265db0a3ad4c)
- Linux — Linux (c5f0c0e7525443add533495e93ba8de6feab2396)
- Linux — Linux (1674b4bf3eea3cac51b70778e89f8025f7cfe695)
- Linux — Linux (3.10.51)
- Linux — Linux (3.12.40)
- Linux — Linux (3.14)
- Linux — Linux (0)
- Linux — Linux (6.12.109)
- Linux — Linux (6.18.50)
- Linux — Linux (7.2.4)
- Linux — Linux (7.3-rc1)
- Linux — Linux (5.10.270)
- Linux — Linux (5.15.221)
- Linux — Linux (6.1.188)
- Linux — Linux (6.6.157)

## References

- [CNA](https://git.kernel.org/stable/c/6767d70cf46f65807a6a4c4406a518e6c12e36ae)
- [CNA](https://git.kernel.org/stable/c/e41a59fc056f63a7a1f42788913c53cc48d744aa)
- [CNA](https://git.kernel.org/stable/c/5d85eef222cfd28e73deed7402c100229e8b9e6e)
- [CNA](https://git.kernel.org/stable/c/0dbc2398fca3bb33eda963849f865ddb1b3aa05e)
- [CNA](https://git.kernel.org/stable/c/5de5d554141a15b3f1f5c978fd9f7f4fd6d0600a)
- [CNA](https://git.kernel.org/stable/c/48db11e115d1b232edc5591604adc6eda95cd545)
- [CNA](https://git.kernel.org/stable/c/4477222e2916a18e273edc139c955ade6bbb7a69)
- [CNA](https://git.kernel.org/stable/c/4d5c460ef8754be1d43b16dbf02695b008b207d6)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.13%
- **EPSS Percentile:** 2.9

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._