{"id":"CVE-2026-90142","published":"2026-09-17T17:17:06.990","lastModified":"2026-09-18T18:17:43.567","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nvirtio_net: Fix resize of the RX ring\n\nWhen a AF_XDP socket is attached, the virtnet_rx_resize\nshould resize the rq->xsk_buffs XSK buffer array. Otherwise,\nwhen the size grows, the virtnet_rx_resume() causes a write\npast the end of the array. This is easily reproducable with\n\n    ethtool -G ens3 rx 32\n    ./xdpsock -i eth0 -q 0 -r -z &\n    ethtool -G eth0 rx 256","cvssScore":7.8,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwes":[],"vendors":[],"products":[],"references":[{"url":"https://git.kernel.org/stable/c/8344c9233c8f77017174d9e280c5a26034d068b6","tags":[]},{"url":"https://git.kernel.org/stable/c/d09c98a6da215bce2173a292e4b95c8de6ea5d51","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}