Vulnerability
Published 2026-09-17
Verified 2026-09-19

Open vSwitch strips SKBFL_SHARED_FRAG — Dirty COW-class decrypt write (CVE-2026-90049/89487/80977)

Doyensec research post (17 September 2026) shows Open vSwitch’s kernel datapath can strip SKBFL_SHARED_FRAG from a still-forwarded packet, re-opening the Fragnesia Dirty COW-class primitive: an unprivileged user can cause in-place ESP decrypt over page-cache pages they may only read, writing attacker-chosen bytes into root-owned file page cache. Tracked as CVE-2026-90049, CVE-2026-89487 and CVE-2026-80977; reported to the Linux kernel security team and coordinated with OVS maintainers. Builds on prior Dirty Frag / Fragnesia work (including CVE-2026-43284 and CVE-2026-43500). Impact surface: virtualisation/container stacks using OVS (OpenStack Neutron, oVirt, Antrea/OVN-Kubernetes, libvirt bridges, etc.). Primary: Doyensec blog; await distro/kernel OVS package advisories for fixed revisions.

Product
Open vSwitch kernel datapath (openvswitch.ko) / Linux networking
Versions
Affected OVS/kernel builds prior to coordinated fixes for CVE-2026-90049 / CVE-2026-89487 / CVE-2026-80977 (exact package versions per distro advisory)
Exploited in Australia?
unknown
Patch to
Apply vendor/distro kernel and openvswitch updates once published for CVE-2026-90049/89487/80977; until then restrict untrusted local users on OVS hosts and monitor kernel security ML

Primary: Doyensec — OVS shared-frag / Fragnesia re-open (17 Sep 2026) · Vendor: Open vSwitch project · CVE: CVE-2026-90049, CVE-2026-89487, CVE-2026-80977, CVE-2026-43284, CVE-2026-43500 · Talkback — linked Doyensec OVS post (desk wire)

vulnerabilities network cloud