In the Linux kernel, the following vulnerability has been resolved: tun: free page on short-frame rejection in tun_xdp_one() tun_xdp_one() returns -EINVAL on a frame shorter than ETH_HLEN without freeing the page that vhost_net_build_xdp() allocated for it. tun_sendmsg() discards that -EINVAL and still returns total_len, so vhost_tx_batch() takes the success path and never frees the page; each short frame in a batch leaks one page-frag chunk. A local process that can open /dev/net/tun and /dev/vhost-net can hit this path: it attaches a tun/tap device as the vhost-net backend and feeds TX descriptors whose length minus the virtio-net header is below ETH_HLEN. Each kick leaks the page-frag chunks for that batch, and a tight submission loop exhausts host memory and triggers an OOM panic. Free the page before returning -EINVAL, matching the XDP-program error path in the same function.
Update Linux/Linux to 0a6f46a9332ad6958992d64d3b3a81a80b2ca940 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scantun: free page on short-frame rejection in tun_xdp_one() affects Linux/Linux (generic), Linux/Linux (generic). Severity is high. In the Linux kernel, the following vulnerability has been resolved: tun: free page on short-frame rejection in tun_xdp_one() tun_xdp_one() returns -EINVAL on a frame shorter than ETH_HLEN without freeing the page that vhost_net_build_xdp() allocated for it. tun_sendmsg() discards that -EINVAL and still returns total_len, so vhost_tx_batch() takes the success path and never frees the page; each short frame in a batch leaks one page-frag chunk. A local process that can open /dev/net/tun and /dev/vhost-net can hit this path: it attaches a tun/tap device as the vhost-net backend and feeds TX descriptors whose length minus the virtio-net header is below ETH_HLEN. Each kick leaks the page-frag chunks for that batch, and a tight submission loop exhausts host memory and triggers an OOM panic. Free the page before returning -EINVAL, matching the XDP-program error path in the same function.
AI coding agents often install or upgrade packages automatically in generic. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package |
|---|
In the Linux kernel, the following vulnerability has been resolved: tun: free page on short-frame rejection in tun_xdp_one() tun_xdp_one() returns -EINVAL on a frame shorter than ETH_HLEN without freeing the page that vhost_net_build_xdp() allocated for it. tun_sendmsg() discards that -EINVAL and still returns total_len, so vhost_tx_batch() takes the success path and never frees the page; each short frame in a batch leaks one page-frag chunk. A local process that can open /dev/net/tun and /dev/vhost-net can hit this path: it attaches a tun/tap device as the vhost-net backend and feeds TX descriptors whose length minus the virtio-net header is below ETH_HLEN. Each kick leaks the page-frag chunks for that batch, and a tight submission loop exhausts host memory and triggers an OOM panic. Free the page before returning -EINVAL, matching the XDP-program error path in the same function.
Update Linux/Linux to 0a6f46a9332ad6958992d64d3b3a81a80b2ca940 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scantun: free page on short-frame rejection in tun_xdp_one() affects Linux/Linux (generic), Linux/Linux (generic). Severity is high. In the Linux kernel, the following vulnerability has been resolved: tun: free page on short-frame rejection in tun_xdp_one() tun_xdp_one() returns -EINVAL on a frame shorter than ETH_HLEN without freeing the page that vhost_net_build_xdp() allocated for it. tun_sendmsg() discards that -EINVAL and still returns total_len, so vhost_tx_batch() takes the success path and never frees the page; each short frame in a batch leaks one page-frag chunk. A local process that can open /dev/net/tun and /dev/vhost-net can hit this path: it attaches a tun/tap device as the vhost-net backend and feeds TX descriptors whose length minus the virtio-net header is below ETH_HLEN. Each kick leaks the page-frag chunks for that batch, and a tight submission loop exhausts host memory and triggers an OOM panic. Free the page before returning -EINVAL, matching the XDP-program error path in the same function.
AI coding agents often install or upgrade packages automatically in generic. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package |
|---|
| Affected range |
|---|
| Fixed version |
|---|
| Linux/Linuxgeneric | >=6100e0237204890269e3f934acfc50d35fd6f319 <0a6f46a9332ad6958992d64d3b3a81a80b2ca940 || >=589382f50b4a5d90d16d8bc9dcbc0e927a3e39b2 <0e8211fcf9426f5adddf32516ba0f400ceb9544d || >=ad6b3f622ccfb4bfedfa53b6ebd91c3d1d04f146 <e915445942af6dcea628bf66d6241641201a0c41 || >=d5ad89b7d01ed4e66fd04734fc63d6e78536692a <5b34f9e4fe2f203724a6e893d6df0316b9670057 || >=049584807f1d797fc3078b68035450a9769eb5c3 <69863ff2720a0e9871f1a5710f2a33a94217fee0 || >=049584807f1d797fc3078b68035450a9769eb5c3 <37a1c268c2c8090bf4dc552d732bd23ba36f8eb0 || >=049584807f1d797fc3078b68035450a9769eb5c3 <98c67be9eb9de72465a071949e84a3cdb8fab5a3 || >=049584807f1d797fc3078b68035450a9769eb5c3 <f4feb1e20058e407cb00f45aff47f5b7e19a6bbf || 32b0aaba5dbc85816898167d9b5d45a22eae82e9 || a9d1c27e2ee3b0ea5d40c105d6e728fc114470bb || 8418f55302fa1d2eeb73e16e345167e545c598a5 || >=5.10.223 <5.10.259 || >=5.15.164 <5.15.210 || >=6.1.102 <6.1.176 || >=6.6.43 <6.6.143 || >=5.4.281 <5.5 || >=6.9.12 <6.10 || >=6.10.2 <6.11 | 0a6f46a9332ad6958992d64d3b3a81a80b2ca940, 0e8211fcf9426f5adddf32516ba0f400ceb9544d, e915445942af6dcea628bf66d6241641201a0c41, 5b34f9e4fe2f203724a6e893d6df0316b9670057, 69863ff2720a0e9871f1a5710f2a33a94217fee0, 37a1c268c2c8090bf4dc552d732bd23ba36f8eb0, 98c67be9eb9de72465a071949e84a3cdb8fab5a3, f4feb1e20058e407cb00f45aff47f5b7e19a6bbf, 5.10.259, 5.15.210, 6.1.176, 6.6.143, 5.5, 6.10, 6.11 |
|---|---|---|
| Linux/Linuxgeneric | 6.11 | Not reported |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by CVE List V5 (cvelist).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard| Affected range |
|---|
| Fixed version |
|---|
| Linux/Linuxgeneric | >=6100e0237204890269e3f934acfc50d35fd6f319 <0a6f46a9332ad6958992d64d3b3a81a80b2ca940 || >=589382f50b4a5d90d16d8bc9dcbc0e927a3e39b2 <0e8211fcf9426f5adddf32516ba0f400ceb9544d || >=ad6b3f622ccfb4bfedfa53b6ebd91c3d1d04f146 <e915445942af6dcea628bf66d6241641201a0c41 || >=d5ad89b7d01ed4e66fd04734fc63d6e78536692a <5b34f9e4fe2f203724a6e893d6df0316b9670057 || >=049584807f1d797fc3078b68035450a9769eb5c3 <69863ff2720a0e9871f1a5710f2a33a94217fee0 || >=049584807f1d797fc3078b68035450a9769eb5c3 <37a1c268c2c8090bf4dc552d732bd23ba36f8eb0 || >=049584807f1d797fc3078b68035450a9769eb5c3 <98c67be9eb9de72465a071949e84a3cdb8fab5a3 || >=049584807f1d797fc3078b68035450a9769eb5c3 <f4feb1e20058e407cb00f45aff47f5b7e19a6bbf || 32b0aaba5dbc85816898167d9b5d45a22eae82e9 || a9d1c27e2ee3b0ea5d40c105d6e728fc114470bb || 8418f55302fa1d2eeb73e16e345167e545c598a5 || >=5.10.223 <5.10.259 || >=5.15.164 <5.15.210 || >=6.1.102 <6.1.176 || >=6.6.43 <6.6.143 || >=5.4.281 <5.5 || >=6.9.12 <6.10 || >=6.10.2 <6.11 | 0a6f46a9332ad6958992d64d3b3a81a80b2ca940, 0e8211fcf9426f5adddf32516ba0f400ceb9544d, e915445942af6dcea628bf66d6241641201a0c41, 5b34f9e4fe2f203724a6e893d6df0316b9670057, 69863ff2720a0e9871f1a5710f2a33a94217fee0, 37a1c268c2c8090bf4dc552d732bd23ba36f8eb0, 98c67be9eb9de72465a071949e84a3cdb8fab5a3, f4feb1e20058e407cb00f45aff47f5b7e19a6bbf, 5.10.259, 5.15.210, 6.1.176, 6.6.143, 5.5, 6.10, 6.11 |
|---|---|---|
| Linux/Linuxgeneric | 6.11 | Not reported |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by CVE List V5 (cvelist).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard