CVE-2026-31429 Details
Description
In the Linux kernel, the following vulnerability has been resolved: net: skb: fix cross-cache free of KFENCE-allocated skb head SKB_SMALL_HEAD_CACHE_SIZE is intentionally set to a non-power-of-2 value (e.g. 704 on x86_64) to avoid collisions with generic kmalloc bucket sizes. This ensures that skb_kfree_head() can reliably use skb_end_offset to distinguish skb heads allocated from skb_small_head_cache vs. generic kmalloc caches. However, when KFENCE is enabled, kfence_ksize() returns the exact requested allocation size instead of the slab bucket size. If a caller (e.g. bpf_test_init) allocates skb head data via kzalloc() and the requested size happens to equal SKB_SMALL_HEAD_CACHE_SIZE, then slab_build_skb() -> ksize() returns that exact value. After subtracting skb_shared_info overhead, skb_end_offset ends up matching SKB_SMALL_HEAD_HEADROOM, causing skb_kfree_head() to incorrectly free the object to skb_small_head_cache instead of back to the original kmalloc cache, resulting in a slab cross-cache free: kmem_cache_free(skbuff_small_head): Wrong slab cache. Expected skbuff_small_head but got kmalloc-1k Fix this by always calling kfree(head) in skb_kfree_head(). This keeps the free path generic and avoids allocator-specific misclassification for KFENCE objects.
A vulnerability in the Linux kernel's handling of socket buffer (SKB) heads allocated with KFENCE enabled has been fixed. The issue arose because SKB_SMALL_HEAD_CACHE_SIZE is set to a non-power-of-2 value to prevent collisions with generic kmalloc bucket sizes. This allows skb_kfree_head() to accurately distinguish between SKB heads from the small head cache and those from generic kmalloc caches. However, with KFENCE enabled, the kfence_ksize() function returns the exact allocation size instead of the slab bucket size. If a caller allocates SKB head data via kzalloc() and the size matches SKB_SMALL_HEAD_CACHE_SIZE, it leads to a misclassification. This causes skb_kfree_head() to incorrectly free the object to the small head cache instead of the original kmalloc cache, resulting in a slab cross-cache free error. The vulnerability has been addressed by modifying skb_kfree_head() to always call kfree(head), ensuring a generic free path that avoids allocator-specific errors for KFENCE objects.
Users can apply the latest patches available in the Linux kernel stable tree to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/0f42e3f4fe2a58394e37241d02d9ca6ab7b7d516 | kernel.org | Patch |
| https://git.kernel.org/stable/c/128b03ccb2582a643983a48a37fda58df80edbde | kernel.org | Patch |
| https://git.kernel.org/stable/c/2d64618ea846d8d033477311f805ca487d6a6696 | kernel.org | Patch |
| https://git.kernel.org/stable/c/474e00b935db250cac320d10c1d3cf4e44b46721 | kernel.org | Patch |
| https://git.kernel.org/stable/c/60313768a8edc7094435975587c00c2d7b834083 | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-401 | Missing Release of Memory after Effective Lifetime | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 6.3, < 6.6.136 >= 6.7, < 6.12.82 >= 6.13, < 6.18.23 >= 6.19, < 6.19.13 7.0 rc1 7.0 rc2 7.0 rc3 7.0 rc4 7.0 rc5 7.0 rc6 7.0 rc7 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | kernel.org |
| May 20, 2026 | Initial Analysis | [email protected] |
| Apr 27, 2026 | CVE Modified | kernel.org |
| Apr 20, 2026 | New CVE Received | kernel.org |