Description
In the Linux kernel, the following vulnerability has been resolved:

net/sched: fix pedit partial COW leading to page cache corruption

tcf_pedit_act() computes the COW range for skb_ensure_writable()
once before the key loop using tcfp_off_max_hint, but the hint does
not account for the runtime header offset added by typed keys. This
can leave part of the write region un-COW'd.

Fix by moving skb_ensure_writable() inside the per-key loop where
the actual write offset is known, and add overflow checking on the
offset arithmetic. For negative offsets (e.g. Ethernet header edits
at ingress), use skb_cow() to COW the headroom instead. Guard
offset_valid() against INT_MIN, where negation is undefined.
Published: 2026-06-16
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4665-1 linux security update
Debian DLA Debian DLA DLA-4671-1 linux-6.1 security update
Debian DLA Debian DLA DLA-4717-1 linux security update
Debian DSA Debian DSA DSA-6355-1 linux security update
Ubuntu USN Ubuntu USN USN-8629-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8630-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8631-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8633-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8635-1 Linux kernel (Azure) vulnerabilities
Ubuntu USN Ubuntu USN USN-8636-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8630-2 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8631-2 Linux kernel (Oracle) vulnerabilities
Ubuntu USN Ubuntu USN USN-8637-1 Linux kernel (OEM) vulnerabilities
Ubuntu USN Ubuntu USN USN-8631-3 Linux kernel (NVIDIA Tegra IGX) vulnerabilities
Ubuntu USN Ubuntu USN USN-8633-2 Linux kernel vulnerabilities
References
Link Providers
https://access.redhat.com/errata/RHSA-2026:27288 cve-icon
https://access.redhat.com/errata/RHSA-2026:27353 cve-icon
https://access.redhat.com/errata/RHSA-2026:27354 cve-icon
https://access.redhat.com/errata/RHSA-2026:27355 cve-icon
https://access.redhat.com/errata/RHSA-2026:27704 cve-icon
https://access.redhat.com/errata/RHSA-2026:27705 cve-icon
https://access.redhat.com/errata/RHSA-2026:27706 cve-icon
https://access.redhat.com/errata/RHSA-2026:27707 cve-icon
https://access.redhat.com/errata/RHSA-2026:27708 cve-icon
https://access.redhat.com/errata/RHSA-2026:27709 cve-icon
https://access.redhat.com/errata/RHSA-2026:27713 cve-icon
https://access.redhat.com/errata/RHSA-2026:27731 cve-icon
https://access.redhat.com/errata/RHSA-2026:27789 cve-icon
https://access.redhat.com/errata/RHSA-2026:28887 cve-icon
https://access.redhat.com/errata/RHSA-2026:28962 cve-icon
https://access.redhat.com/errata/RHSA-2026:29080 cve-icon
https://access.redhat.com/errata/RHSA-2026:29794 cve-icon
https://access.redhat.com/errata/RHSA-2026:29799 cve-icon
https://access.redhat.com/errata/RHSA-2026:29833 cve-icon
https://access.redhat.com/errata/RHSA-2026:29856 cve-icon
https://access.redhat.com/errata/RHSA-2026:29863 cve-icon
https://access.redhat.com/errata/RHSA-2026:33219 cve-icon
https://access.redhat.com/errata/RHSA-2026:33220 cve-icon
https://access.redhat.com/errata/RHSA-2026:33221 cve-icon
https://access.redhat.com/errata/RHSA-2026:33222 cve-icon
https://access.redhat.com/errata/RHSA-2026:33223 cve-icon
https://access.redhat.com/errata/RHSA-2026:33224 cve-icon
https://access.redhat.com/errata/RHSA-2026:33225 cve-icon
https://access.redhat.com/errata/RHSA-2026:33666 cve-icon
https://access.redhat.com/errata/RHSA-2026:34048 cve-icon
https://access.redhat.com/errata/RHSA-2026:34098 cve-icon
https://access.redhat.com/errata/RHSA-2026:40021 cve-icon
https://access.redhat.com/security/cve/CVE-2026-46331 cve-icon
https://bugzilla.redhat.com/show_bug.cgi?id=2479492 cve-icon
https://git.kernel.org/stable/c/2bec122b9fb91507a758ab5e3e5c4fbe7cb3f61b cve-icon cve-icon
https://git.kernel.org/stable/c/3dee9d0c198faeb95d052c1b94c2958751a28512 cve-icon cve-icon
https://git.kernel.org/stable/c/544d857b42a1734b923040e13aa61a6fd4746cf2 cve-icon cve-icon
https://git.kernel.org/stable/c/899ee91156e57784090c5565e4f31bd7dbffbc5a cve-icon cve-icon
https://git.kernel.org/stable/c/a071e057518decc5e3bec89855758f5f8786f2c5 cve-icon cve-icon
https://git.kernel.org/stable/c/b198ed4e52580a7238c7c7082f03906f8b310313 cve-icon cve-icon
https://git.kernel.org/stable/c/b685d6ef6f07a3b5ce814565a25f39f2157538a5 cve-icon cve-icon
https://git.kernel.org/stable/c/d5d01d35a5a7d36f7cb679b67d9cbdd5205672dc cve-icon cve-icon
https://github.com/sgkdev/packet_edit_meme/tree/main cve-icon cve-icon
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-46331.json cve-icon
History

Sat, 04 Jul 2026 12:15:00 +0000


Mon, 29 Jun 2026 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119

Mon, 29 Jun 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-190
CWE-787
References
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sun, 28 Jun 2026 13:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119

Sun, 28 Jun 2026 10:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-122
CWE-787

Sun, 28 Jun 2026 08:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Fri, 19 Jun 2026 12:45:00 +0000


Thu, 18 Jun 2026 04:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-122
CWE-787

Tue, 16 Jun 2026 08:00:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: net/sched: fix pedit partial COW leading to page cache corruption tcf_pedit_act() computes the COW range for skb_ensure_writable() once before the key loop using tcfp_off_max_hint, but the hint does not account for the runtime header offset added by typed keys. This can leave part of the write region un-COW'd. Fix by moving skb_ensure_writable() inside the per-key loop where the actual write offset is known, and add overflow checking on the offset arithmetic. For negative offsets (e.g. Ethernet header edits at ingress), use skb_cow() to COW the headroom instead. Guard offset_valid() against INT_MIN, where negation is undefined.
Title net/sched: fix pedit partial COW leading to page cache corruption
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-05T12:31:25.966Z

Reserved: 2026-05-13T15:03:33.112Z

Link: CVE-2026-46331

cve-icon Vulnrichment

Updated: 2026-07-23T12:08:07.840Z

cve-icon NVD

Status : Modified

Published: 2026-06-16T08:16:23.993

Modified: 2026-07-23T12:18:18.287

Link: CVE-2026-46331

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-29T17:30:06Z

Weaknesses