CVE-2026-81002
CVE-2026-81002 is a critical flaw in the Linux kernel's XDP zero-copy packet handling. When an AF_XDP packet is redirected through a CPU map, packet data can be placed in the wrong part of its memory page, potentially causing memory corruption and a kernel panic.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Linux kernel systems using the affected XDP zero-copy packet-handling path. The supplied data does not list affected products or versions.
Real-world impact
The flaw can lead to memory corruption and a kernel panic on affected Linux kernel systems.
Why this severity
The vulnerability is rated critical because it can be exploited remotely, requires no prior access or user action, and can affect confidentiality, integrity, and availability.
What to do about it
- 01Install a Linux kernel update containing the fix titled xdp: fix zero-copy frame layout.
The NVD description states that the vulnerability was resolved by the Linux kernel fix titled xdp: fix zero-copy frame layout; it does not identify affected versions or a specific patch.
Timeline
- Sep 11, 2026 · 2d agoPublishedDisclosed and added to the National Vulnerability Database.
- Sep 13, 2026 · 5h agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.