CVE-2026-53216 Details
Description
In the Linux kernel, the following vulnerability has been resolved: net: mvpp2: limit XDP frame size to the RX buffer mvpp2 has short and long BM pools, and short pool buffers can be smaller than PAGE_SIZE. The XDP path nevertheless initializes every xdp_buff with PAGE_SIZE as frame size. XDP helpers use frame_sz to validate tail growth and to derive the hard end of the data area. Advertising PAGE_SIZE for short buffers can let bpf_xdp_adjust_tail() grow a packet past the real allocation, corrupting memory or later tripping skb tailroom checks. Initialize the XDP buffer with bm_pool->frag_size so XDP tailroom matches the actual buffer backing the packet.
A vulnerability in the Linux kernel's MVPP2 Ethernet driver allows for improper validation of XDP (eXpress Data Path) frame sizes, potentially leading to memory corruption. This issue arises because MVPP2's short buffer pool can have buffers smaller than the standard page size. However, the XDP implementation incorrectly initializes each XDP buffer with the full page size. As a result, XDP helpers might allow packets to grow beyond their actual allocated size, causing memory corruption or violating socket buffer tailroom checks. The vulnerability affects the Linux kernel stable group.
Users can update to the latest version of the Linux kernel where this vulnerability has been addressed. Instructions for downloading the patched version are available on the official Linux kernel website.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/3b8b0c3631b19faee53f0d15a49924129b063eec | kernel.org | Patch |
| https://git.kernel.org/stable/c/910617a4e67dbdd5fdb39d9dc6a51e491e1b2c3e | kernel.org | Patch |
| https://git.kernel.org/stable/c/9545cc5ef18ca22d031f2f47c157192460652359 | kernel.org | Patch |
| https://git.kernel.org/stable/c/994bd2b58d2bd08aa97ec0836cc813cfcb00d749 | kernel.org | Patch |
| https://git.kernel.org/stable/c/a3ee9231ccec6ec3be2de89c56f897055fd9eab1 | kernel.org | Patch |
| https://git.kernel.org/stable/c/ec8e1e5842bc0dbd4c272761f4db3651eecd0339 | kernel.org | Patch |
| https://git.kernel.org/stable/c/f3c6aa078927e6fe8121c9c591ddee8716c5305a | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 5.9, < 5.15.210 >= 5.16, < 6.1.176 >= 6.2, < 6.6.143 >= 6.7, < 6.12.94 >= 6.13, < 6.18.36 >= 6.19, < 7.0.13 7.1 rc1 7.1 rc2 7.1 rc3 7.1 rc4 7.1 rc5 7.1 rc6 7.1 rc7 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 2, 2026 | Initial Analysis | [email protected] |
| Jun 28, 2026 | CVE Modified | kernel.org |
| Jun 25, 2026 | New CVE Received | kernel.org |