PatchSiren cyber security CVE debrief
CVE-2026-90049 Linux CVE debrief
A vulnerability in the Linux kernel's network stack has been addressed. The `skb_zerocopy()` function did not properly handle errors, potentially leading to incorrect handling of shared fragments. This could impact the decryption process for ESP (Encapsulating Security Payload) packets. The issue arises from the function's failure to properly manage shared fragments when errors occur, which can affect the decryption process for ESP packets. Linux kernel maintainers and users should assess exposure and verify patches.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- CRITICAL 9.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-16
- Original CVE updated
- 2026-09-28
- Advisory published
- 2026-09-16
- Advisory updated
- 2026-09-28
Who should care
Linux kernel maintainers, users, and network administrators should assess exposure and verify patches. This vulnerability affects Linux kernel configurations, and users should review patch notes and assess exposure. Linux kernel maintainers and users should assess exposure and verify patches to prevent potential ESP packet handling issues.
Why it matters
A vulnerability in the Linux kernel's network stack has been addressed, potentially impacting ESP packet decryption. Linux kernel maintainers and users should assess exposure and verify patches.
- Verify patch levels to prevent potential ESP packet handling issues
- Assess exposure and prioritize patching for Linux kernel configurations
Technical summary
The `skb_zerocopy()` function in the Linux kernel did not properly handle errors, potentially leading to incorrect handling of shared fragments. This could impact the decryption process for ESP packets. The issue arises from the function's failure to properly manage shared fragments when errors occur, which can affect the decryption process for ESP packets. Linux kernel maintainers and users should assess exposure and verify patches. The vulnerability has been addressed, and Linux kernel maintainers, users, and network administrators should assess exposure and verify patches.
Defensive priority
Linux kernel maintainers and users should assess exposure and verify patches.
Recommended defensive actions
- Review Linux kernel patch notes and assess exposure
- Verify system configurations and patch levels
- Monitor network traffic for unusual ESP packet handling
- Assess exposure and prioritize patching for Linux kernel configurations
- Verify patch levels to prevent potential ESP packet handling issues
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record and NVD entry provide details on the vulnerability. Multiple source references from the Linux kernel Git repository are available. The issue is related to the `skb_zerocopy()` function in the Linux kernel, which did not properly handle errors. This vulnerability has been addressed, and Linux kernel maintainers, users, and network administrators should assess exposure and verify patches. The CVE record and NVD entry provide details on the vulnerability.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-90049 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-90049
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-90049 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-90049
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/04dd250a78e268af3e7124beb1dc10ec1dd88d60
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/767ec2a65cc022d303b0c9c12811e7db22057341
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/8069643ae64dfdf634b6c78c7f622e5323031436
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/849bdb83123760a865bcb2970127f4c0b9423ba3
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/8ece906150128d5ec2462aabcc978c568433eca4
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/a13b1e80e5015cd732440b475c0ef443dc4a2157
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/bab5a851e44a3601d31f2aa8043f385bb50ac5d9
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/fb10e0e9b220a2eed08931a60dbaad9a2370c908
416baaa9-dc9f-4396-8d5f-8c081fb06d67
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.