CVE-2026-53216
published 2026-06-25CVE-2026-53216: In the Linux kernel, the following vulnerability has been resolved: net: mvpp2: limit XDP frame size to the RX buffer mvpp2 has short and long BM pools, and…
PriorityP354critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.55%
42.0th percentile
In the Linux kernel, the following vulnerability has been resolved:
net: mvpp2: limit XDP frame size to the RX buffer
mvpp2 has short and long BM pools, and short pool buffers can be smaller
than PAGE_SIZE. The XDP path nevertheless initializes every xdp_buff with
PAGE_SIZE as frame size.
XDP helpers use frame_sz to validate tail growth and to derive the hard
end of the data area. Advertising PAGE_SIZE for short buffers can let
bpf_xdp_adjust_tail() grow a packet past the real allocation, corrupting
memory or later tripping skb tailroom checks.
Initialize the XDP buffer with bm_pool->frag_size so XDP tailroom matches
the actual buffer backing the packet.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| linux | linux | — | — |
| linux | linux | >= 07dd0a7aae7f72af7cec18909581c2bb570edddc < a3ee9231ccec6ec3be2de89c56f897055fd9eab1 | a3ee9231ccec6ec3be2de89c56f897055fd9eab1 |
| linux | linux | >= 07dd0a7aae7f72af7cec18909581c2bb570edddc < ec8e1e5842bc0dbd4c272761f4db3651eecd0339 | ec8e1e5842bc0dbd4c272761f4db3651eecd0339 |
| linux | linux | >= 07dd0a7aae7f72af7cec18909581c2bb570edddc < 3b8b0c3631b19faee53f0d15a49924129b063eec | 3b8b0c3631b19faee53f0d15a49924129b063eec |
| linux | linux | >= 07dd0a7aae7f72af7cec18909581c2bb570edddc < 994bd2b58d2bd08aa97ec0836cc813cfcb00d749 | 994bd2b58d2bd08aa97ec0836cc813cfcb00d749 |
| linux | linux | >= 07dd0a7aae7f72af7cec18909581c2bb570edddc < 910617a4e67dbdd5fdb39d9dc6a51e491e1b2c3e | 910617a4e67dbdd5fdb39d9dc6a51e491e1b2c3e |
| linux | linux | >= 07dd0a7aae7f72af7cec18909581c2bb570edddc < 9545cc5ef18ca22d031f2f47c157192460652359 | 9545cc5ef18ca22d031f2f47c157192460652359 |
| linux | linux | >= 07dd0a7aae7f72af7cec18909581c2bb570edddc < f3c6aa078927e6fe8121c9c591ddee8716c5305a | f3c6aa078927e6fe8121c9c591ddee8716c5305a |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 5.16 < 6.1.176 | 6.1.176 |
| linux | linux_kernel | >= 5.9 < 5.15.210 | 5.15.210 |
| linux | linux_kernel | >= 6.13 < 6.18.36 | 6.18.36 |
| linux | linux_kernel | >= 6.19 < 7.0.13 | 7.0.13 |
| linux | linux_kernel | >= 6.2 < 6.6.143 | 6.6.143 |
| linux | linux_kernel | >= 6.7 < 6.12.94 | 6.12.94 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: net: mvpp2: limit XDP frame size to the RX buffer
vendor_redhat·2026-06-25
CVE-2026-53216 CWE-787 kernel: net: mvpp2: limit XDP frame size to the RX buffer
kernel: net: mvpp2: limit XDP frame size to the RX buffer
In the Linux kernel, the following vulnerability has been resolved:
net: mvpp2: limit XDP frame size to the RX buffer
mvpp2 has short and long BM pools, and short pool buffers can be smaller
than PAGE_SIZE. The XDP path nevertheless initializes every xdp_buff with
PAGE_SIZE as frame size.
XDP helpers use frame_sz to validate tail growth and to derive the hard
end of the data area. Advertising PAGE_SIZE for short buffers can let
bpf_xdp_adjust_tail() grow a packet past the real allocation, corrupting
memory or later tripping skb tailroom checks.
Initialize the XDP buffer with bm_pool->frag_size so XDP tailroom matches
the actual buffer backing the packet.
A flaw was found in the Linux kernel's mvpp2 network driver. This vulnerabili
GHSA
In the Linux kernel, the following vulnerability has been resolved: net: mvpp2: limit XDP frame size to the RX buffer mvpp2 has short and long BM pools, and short pool buffers can be smaller than PA
ghsa_unreviewed·2026-06-25
CVE-2026-53216 In the Linux kernel, the following vulnerability has been resolved: net: mvpp2: limit XDP frame size to the RX buffer mvpp2 has short and long BM pools, and short pool buffers can be smaller than PA
In the Linux kernel, the following vulnerability has been resolved:
net: mvpp2: limit XDP frame size to the RX buffer
mvpp2 has short and long BM pools, and short pool buffers can be smaller
than PAGE_SIZE. The XDP path nevertheless initializes every xdp_buff with
PAGE_SIZE as frame size.
XDP helpers use frame_sz to validate tail growth and to derive the hard
end of the data area. Advertising PAGE_SIZE for short buffers can let
bpf_xdp_adjust_tail() grow a packet past the real allocation, corrupting
memory or later tripping skb tailroom checks.
Initialize the XDP buffer with bm_pool->frag_size so XDP tailroom matches
the actual buffer backing the packet.
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/3b8b0c3631b19faee53f0d15a49924129b063eechttps://git.kernel.org/stable/c/910617a4e67dbdd5fdb39d9dc6a51e491e1b2c3ehttps://git.kernel.org/stable/c/9545cc5ef18ca22d031f2f47c157192460652359https://git.kernel.org/stable/c/994bd2b58d2bd08aa97ec0836cc813cfcb00d749https://git.kernel.org/stable/c/a3ee9231ccec6ec3be2de89c56f897055fd9eab1https://git.kernel.org/stable/c/ec8e1e5842bc0dbd4c272761f4db3651eecd0339https://git.kernel.org/stable/c/f3c6aa078927e6fe8121c9c591ddee8716c5305a
2026-06-25
Published