CVE-2026-46300
Linux Linux, NVIDIA for RHEL 10, Red Hat Enterprise Linux 10
In the Linux kernel, the following vulnerability has been resolved: net: skbuff: preserve shared-frag marker during coalescing skb_try_coalesce() can attach paged frags from @from to @to. If @from has SKBFL_SHARED_FRAG set, the resulting @to skb can contain the same externally-owned or page-cache-backed frags, but the shared-frag marker is currently lost. That breaks the invariant relied on by later in-place writers. In particular, ESP input checks skb_has_shared_frag() before deciding whether an uncloned nonlinear skb can skip skb_cow_data(). If TCP receive coalescing has moved shared frag...
- CVSS
- 7.8
- EPSS
- 7.01% 93.5% percentile
- CISA KEV
- Not listed
- Published
- 2026.05.23