Linux Kernel tun: page leak on build_skb fail in tun_xdp_one()
CVE-2026-46322 Published on June 9, 2026
tun: free page on build_skb failure in tun_xdp_one()
In the Linux kernel, the following vulnerability has been resolved:
tun: free page on build_skb failure in tun_xdp_one()
When build_skb() fails in tun_xdp_one(), the function sets ret to
-ENOMEM and jumps to the out label, which returns without freeing the
page that vhost_net_build_xdp() allocated for the frame. As with the
short-frame rejection path, tun_sendmsg() discards the per-buffer error
and still returns total_len, so vhost_tx_batch() takes the success path
and never frees the page. Each build_skb() failure in a batch leaks one
page-frag chunk.
Free the page before taking the error path, matching the put_page() the
other error exits of tun_xdp_one() already perform.
Products Associated with CVE-2026-46322
Want to know whenever a new CVE is published for Linux Kernel? stack.watch will email you.
Affected Versions
Linux:- Version 043d222f93ab8c76b56a3b315cd8692e35affb6c and below d16e38fac09a47bfcf98c1ad65a1bb53f94540f5 is affected.
- Version 043d222f93ab8c76b56a3b315cd8692e35affb6c and below aa308e9dbb9acb17cacdbbce9e4504f69bac8385 is affected.
- Version 043d222f93ab8c76b56a3b315cd8692e35affb6c and below 4fefc6156a162a9f50035c12091a5e5130c82c6e is affected.
- Version 043d222f93ab8c76b56a3b315cd8692e35affb6c and below aa8963fdce667a42fb7f0bdd2909fadcab02f9a8 is affected.
- Version 4.20 is affected.
- Before 4.20 is unaffected.
- Version 6.12.93, <= 6.12.* is unaffected.
- Version 6.18.35, <= 6.18.* is unaffected.
- Version 7.0.12, <= 7.0.* is unaffected.
- Version 7.1-rc6, <= * is unaffected.