PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-90049 Linux CVE debrief

A vulnerability in the Linux kernel's network stack has been addressed. The `skb_zerocopy()` function did not properly handle errors, potentially leading to incorrect handling of shared fragments. This could impact the decryption process for ESP (Encapsulating Security Payload) packets. The issue arises from the function's failure to properly manage shared fragments when errors occur, which can affect the decryption process for ESP packets. Linux kernel maintainers and users should assess exposure and verify patches.

Vendor
Linux
Product
Unknown
CVSS
CRITICAL 9.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-16
Original CVE updated
2026-09-28
Advisory published
2026-09-16
Advisory updated
2026-09-28

Who should care

Linux kernel maintainers, users, and network administrators should assess exposure and verify patches. This vulnerability affects Linux kernel configurations, and users should review patch notes and assess exposure. Linux kernel maintainers and users should assess exposure and verify patches to prevent potential ESP packet handling issues.

Why it matters

A vulnerability in the Linux kernel's network stack has been addressed, potentially impacting ESP packet decryption. Linux kernel maintainers and users should assess exposure and verify patches.

  • Verify patch levels to prevent potential ESP packet handling issues
  • Assess exposure and prioritize patching for Linux kernel configurations

Technical summary

The `skb_zerocopy()` function in the Linux kernel did not properly handle errors, potentially leading to incorrect handling of shared fragments. This could impact the decryption process for ESP packets. The issue arises from the function's failure to properly manage shared fragments when errors occur, which can affect the decryption process for ESP packets. Linux kernel maintainers and users should assess exposure and verify patches. The vulnerability has been addressed, and Linux kernel maintainers, users, and network administrators should assess exposure and verify patches.

Defensive priority

Linux kernel maintainers and users should assess exposure and verify patches.

Recommended defensive actions

  • Review Linux kernel patch notes and assess exposure
  • Verify system configurations and patch levels
  • Monitor network traffic for unusual ESP packet handling
  • Assess exposure and prioritize patching for Linux kernel configurations
  • Verify patch levels to prevent potential ESP packet handling issues
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record and NVD entry provide details on the vulnerability. Multiple source references from the Linux kernel Git repository are available. The issue is related to the `skb_zerocopy()` function in the Linux kernel, which did not properly handle errors. This vulnerability has been addressed, and Linux kernel maintainers, users, and network administrators should assess exposure and verify patches. The CVE record and NVD entry provide details on the vulnerability.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-90049 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-90049

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-90049 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-90049

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/04dd250a78e268af3e7124beb1dc10ec1dd88d60

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/767ec2a65cc022d303b0c9c12811e7db22057341

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/8069643ae64dfdf634b6c78c7f622e5323031436

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/849bdb83123760a865bcb2970127f4c0b9423ba3

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/8ece906150128d5ec2462aabcc978c568433eca4

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/a13b1e80e5015cd732440b475c0ef443dc4a2157

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/bab5a851e44a3601d31f2aa8043f385bb50ac5d9

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/fb10e0e9b220a2eed08931a60dbaad9a2370c908

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.