In the Linux kernel, the following vulnerability has been resolved:

net/sched: fix pedit partial COW leading to page cache corruption

tcf_pedit_act() computes the COW range for skb_ensure_writable()
once before the key loop using tcfp_off_max_hint, but the hint does
not account for the runtime header offset added by typed keys. This
can leave part of the write region un-COW'd.

Fix by moving skb_ensure_writable() inside the per-key loop where
the actual write offset is known, and add overflow checking on the
offset arithmetic. For negative offsets (e.g. Ethernet header edits
at ingress), use skb_cow() to COW the headroom instead. Guard
offset_valid() against INT_MIN, where negation is undefined.
Advisories
Source ID Title
Debian DLA Debian DLA DLA-4665-1 linux security update
Debian DLA Debian DLA DLA-4671-1 linux-6.1 security update
Debian DLA Debian DLA DLA-4717-1 linux security update
Debian DSA Debian DSA DSA-6355-1 linux security update
Ubuntu USN Ubuntu USN USN-8629-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8630-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8631-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8633-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8635-1 Linux kernel (Azure) vulnerabilities
Ubuntu USN Ubuntu USN USN-8636-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8630-2 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8631-2 Linux kernel (Oracle) vulnerabilities
Ubuntu USN Ubuntu USN USN-8637-1 Linux kernel (OEM) vulnerabilities
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References
Link Providers
https://access.redhat.com/errata/RHSA-2026:27288 cve-icon
https://access.redhat.com/errata/RHSA-2026:27353 cve-icon
https://access.redhat.com/errata/RHSA-2026:27354 cve-icon
https://access.redhat.com/errata/RHSA-2026:27355 cve-icon
https://access.redhat.com/errata/RHSA-2026:27704 cve-icon
https://access.redhat.com/errata/RHSA-2026:27705 cve-icon
https://access.redhat.com/errata/RHSA-2026:27706 cve-icon
https://access.redhat.com/errata/RHSA-2026:27707 cve-icon
https://access.redhat.com/errata/RHSA-2026:27708 cve-icon
https://access.redhat.com/errata/RHSA-2026:27709 cve-icon
https://access.redhat.com/errata/RHSA-2026:27713 cve-icon
https://access.redhat.com/errata/RHSA-2026:27731 cve-icon
https://access.redhat.com/errata/RHSA-2026:27789 cve-icon
https://access.redhat.com/errata/RHSA-2026:28887 cve-icon
https://access.redhat.com/errata/RHSA-2026:28962 cve-icon
https://access.redhat.com/errata/RHSA-2026:29080 cve-icon
https://access.redhat.com/errata/RHSA-2026:29794 cve-icon
https://access.redhat.com/errata/RHSA-2026:29799 cve-icon
https://access.redhat.com/errata/RHSA-2026:29833 cve-icon
https://access.redhat.com/errata/RHSA-2026:29856 cve-icon
https://access.redhat.com/errata/RHSA-2026:29863 cve-icon
https://access.redhat.com/errata/RHSA-2026:33219 cve-icon
https://access.redhat.com/errata/RHSA-2026:33220 cve-icon
https://access.redhat.com/errata/RHSA-2026:33221 cve-icon
https://access.redhat.com/errata/RHSA-2026:33222 cve-icon
https://access.redhat.com/errata/RHSA-2026:33223 cve-icon
https://access.redhat.com/errata/RHSA-2026:33224 cve-icon
https://access.redhat.com/errata/RHSA-2026:33225 cve-icon
https://access.redhat.com/errata/RHSA-2026:33666 cve-icon
https://access.redhat.com/errata/RHSA-2026:34048 cve-icon
https://access.redhat.com/errata/RHSA-2026:34098 cve-icon
https://access.redhat.com/errata/RHSA-2026:40021 cve-icon
https://access.redhat.com/security/cve/CVE-2026-46331 cve-icon
https://bugzilla.redhat.com/show_bug.cgi?id=2479492 cve-icon
https://git.kernel.org/stable/c/2bec122b9fb91507a758ab5e3e5c4fbe7cb3f61b cve-icon cve-icon
https://git.kernel.org/stable/c/3dee9d0c198faeb95d052c1b94c2958751a28512 cve-icon cve-icon
https://git.kernel.org/stable/c/544d857b42a1734b923040e13aa61a6fd4746cf2 cve-icon cve-icon
https://git.kernel.org/stable/c/899ee91156e57784090c5565e4f31bd7dbffbc5a cve-icon cve-icon
https://git.kernel.org/stable/c/a071e057518decc5e3bec89855758f5f8786f2c5 cve-icon cve-icon
https://git.kernel.org/stable/c/b198ed4e52580a7238c7c7082f03906f8b310313 cve-icon cve-icon
https://git.kernel.org/stable/c/b685d6ef6f07a3b5ce814565a25f39f2157538a5 cve-icon cve-icon
https://git.kernel.org/stable/c/d5d01d35a5a7d36f7cb679b67d9cbdd5205672dc cve-icon cve-icon
https://github.com/sgkdev/packet_edit_meme/tree/main cve-icon cve-icon
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-46331.json cve-icon
History

Sat, 04 Jul 2026 12:15:00 +0000


Mon, 29 Jun 2026 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119

Mon, 29 Jun 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-190
CWE-787
References
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sun, 28 Jun 2026 13:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119

Sun, 28 Jun 2026 10:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-122
CWE-787

Sun, 28 Jun 2026 08:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Fri, 19 Jun 2026 12:45:00 +0000


Thu, 18 Jun 2026 04:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-122
CWE-787

Tue, 16 Jun 2026 08:00:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: net/sched: fix pedit partial COW leading to page cache corruption tcf_pedit_act() computes the COW range for skb_ensure_writable() once before the key loop using tcfp_off_max_hint, but the hint does not account for the runtime header offset added by typed keys. This can leave part of the write region un-COW'd. Fix by moving skb_ensure_writable() inside the per-key loop where the actual write offset is known, and add overflow checking on the offset arithmetic. For negative offsets (e.g. Ethernet header edits at ingress), use skb_cow() to COW the headroom instead. Guard offset_valid() against INT_MIN, where negation is undefined.
Title net/sched: fix pedit partial COW leading to page cache corruption
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-05T12:31:25.966Z

Reserved: 2026-05-13T15:03:33.112Z

Link: CVE-2026-46331

cve-icon Vulnrichment

Updated: 2026-07-23T12:08:07.840Z

cve-icon NVD

Status : Modified

Published: 2026-06-16T08:16:23.993

Modified: 2026-07-23T12:18:18.287

Link: CVE-2026-46331

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-29T17:30:06Z

Weaknesses