Re: CVE-2026-93105: esp: do not unref managed frag pages in esp_ssg_unref()

From: Pedro Falcato

Date: Fri Sep 25 2026 - 05:30:26 EST


On Thu, Sep 17, 2026 at 05:16:22PM +0100, Greg Kroah-Hartman wrote:
> From: Greg Kroah-Hartman <gregkh@xxxxxxxxxx>
>
> Description
> ===========
>
> In the Linux kernel, the following vulnerability has been resolved:
>
> esp: do not unref managed frag pages in esp_ssg_unref()
>
> esp_ssg_unref() releases the page references held on the source
> scatterlist after the AEAD operation completes. It calls
> skb_page_unref() on every frag page for an out-of-place transform
> (req->src != req->dst), and in the error path of esp_output_tail()
> (already_unref == true) on the request's own scatterlist.
>
> This is wrong when the skb carries managed frags
> (SKBFL_MANAGED_FRAG_REFS). Managed frags are owned by a zerocopy ubuf
> and the skb does not hold a per-frag page reference; io_uring SEND_ZC
> with a registered buffer attaches the bvec pages this way via
> io_sg_from_iter(). The rest of the stack honours this invariant:
> skb_release_data() skips the per-frag unref when SKBFL_MANAGED_FRAG_REFS
> is set, and skb_zcopy_managed() is the guard used at the other unref
> sites.
>
> esp_ssg_unref() is missing that guard, so for a managed-frag skb it
> drops a page reference the skb never acquired. This can underflow the
> page reference count and free a page that is still in use.
>
> Guard the function with skb_zcopy_managed() so both unref paths are
> skipped for managed-frag skbs, matching skb_release_data().
>
> The Linux kernel CVE team has assigned CVE-2026-93105 to this issue.
>
>
> Affected and fixed versions
> ===========================
>
> Issue introduced in 4.11 with commit cac2661c53f35cbe651bef9b07026a5a05ab8ce0 and fixed in 7.2.6 with commit 26b6b14c7a0368e317a1e9fb5144ebe6f8d495cf
> Issue introduced in 4.11 with commit cac2661c53f35cbe651bef9b07026a5a05ab8ce0 and fixed in 7.3-rc1 with commit 21697720ff43b8dfa25b8e8d9ca7f56f4597fc80
>
> Please see https://www.kernel.org for a full list of currently supported
> kernel versions by the kernel community.
>
> Unaffected versions might change over time as fixes are backported to
> older supported kernel versions. The official CVE entry at
> https://cve.org/CVERecord/?id=CVE-2026-93105
> will be updated if fixes are backported, please check that for the most
> up to date information about this issue.
>

I think this CVE needs to be rejected.

commit 0fda52de8bbd4ca9a852c8a7ef6536cf82bd71fd
Author: Steffen Klassert <steffen.klassert@xxxxxxxxxxx>
Date: Mon Aug 17 07:17:58 2026 +0200

Revert "esp: do not unref managed frag pages in esp_ssg_unref()"

This reverts commit 21697720ff43b8dfa25b8e8d9ca7f56f4597fc80.

The patch does not fix the issue completely, so revert for
now and wait for an updated version.

Signed-off-by: Steffen Klassert <steffen.klassert@xxxxxxxxxxx>


--
Pedro