Critical Alert 1 Active Exploit Detected Today

CVE-2026-7273 Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability →
Powered by CVE Watchtower
×

CVE Watchtower

← Back to CVE List

CVE-2026-90160NVD

Vulnerability Summary

In the Linux kernel, the following vulnerability has been resolved:

lwt_bpf: Restore reserved headroom after xmit program

ip_finish_output2() expands an skb to LL_RESERVED_SPACE(dev) before LWT
xmit. An LWT_XMIT BPF program can then modify the skb head and still
return BPF_OK, so bpf_xmit() rechecks the remaining headroom before the
skb continues to neighbour output.

That recheck uses dst->dev->hard_header_len. This is not enough for the
neighbour cached-header path: neigh_hh_output() copies the cached hardware
header using the aligned hh_cache size, HH_DATA_MOD for short headers or
HH_DATA_ALIGN(hh_len) otherwise.

On Ethernet, hard_header_len is 14 but the cached copy needs 16 bytes. If
an LWT_XMIT BPF program calls bpf_skb_change_head(skb, 1, 0), the skb can
still have 15 bytes of headroom after the program. The existing check
accepts that, after which neigh_hh_output() hits its headroom warning and
drops the skb.

Use LL_RESERVED_SPACE(dst->dev) in the post-BPF headroom check to match
the reservation made before LWT xmit.
Severity Level
UNKNOWN
Published Date
Sep 17, 2026
Last Modified
Sep 17, 2026
Exploitation Status
No confirmed exploitation yet
EPSS Score (30-Day)
0.21%Probability
Root Weakness (CWE)
N/A

Affected & Patched Versions

Affected Versions
  • Linux Linux >= 3a0af8fd61f90920f6fa04e4f1e9a6a73c1b4fd2 and < 753e5cdcca5474d230d62bb3489e5168ab27c272
  • Linux Linux >= 3a0af8fd61f90920f6fa04e4f1e9a6a73c1b4fd2 and < c488071c3441fa34f5a87cd6c12ce2cc6304f20e
  • Linux Linux >= 3a0af8fd61f90920f6fa04e4f1e9a6a73c1b4fd2 and < a38c0eb447e2dd0120a2ebcdba470f9505ac8907
  • Linux Linux >= 3a0af8fd61f90920f6fa04e4f1e9a6a73c1b4fd2 and < de2b2004e16f2930eb689175e2c1998b0a68d499
  • Linux Linux >= 3a0af8fd61f90920f6fa04e4f1e9a6a73c1b4fd2 and < 7d043e24520a273c362be5dd7d9c82796879a49b
  • Linux Linux >= 3a0af8fd61f90920f6fa04e4f1e9a6a73c1b4fd2 and < 7cf561843ed0ad57501892a65abb77957e6c800f
  • Linux Linux >= 3a0af8fd61f90920f6fa04e4f1e9a6a73c1b4fd2 and < 179a5b2171573d94a25c9aa8e1c9f9ac352ad316
  • Linux Linux >= 3a0af8fd61f90920f6fa04e4f1e9a6a73c1b4fd2 and < 5fe7007aed9ad069b2bd77e5d0c875c64f5c0269
  • Linux Linux >= 4.10
Patched Versions
  • Linux Linux 753e5cdcca5474d230d62bb3489e5168ab27c272
  • Linux Linux c488071c3441fa34f5a87cd6c12ce2cc6304f20e
  • Linux Linux a38c0eb447e2dd0120a2ebcdba470f9505ac8907
  • Linux Linux de2b2004e16f2930eb689175e2c1998b0a68d499
  • Linux Linux 7d043e24520a273c362be5dd7d9c82796879a49b
  • Linux Linux 7cf561843ed0ad57501892a65abb77957e6c800f
  • Linux Linux 179a5b2171573d94a25c9aa8e1c9f9ac352ad316
  • Linux Linux 5fe7007aed9ad069b2bd77e5d0c875c64f5c0269
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.