7.1

CVE-2026-23204

net/sched: cls_u32: use skb_header_pointer_careful()

In the Linux kernel, the following vulnerability has been resolved:

net/sched: cls_u32: use skb_header_pointer_careful()

skb_header_pointer() does not fully validate negative @offset values.

Use skb_header_pointer_careful() instead.

GangMin Kim provided a report and a repro fooling u32_classify():

BUG: KASAN: slab-out-of-bounds in u32_classify+0x1180/0x11b0
net/sched/cls_u32.c:221
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version >= 2.6.35.1 < 6.6.124
Linux ≫ Linux Kernel Version >= 6.7 < 6.12.70
Linux ≫ Linux Kernel Version >= 6.13 < 6.18.10
Linux ≫ Linux Kernel Version 2.6.35 Update -
Linux ≫ Linux Kernel Version 2.6.35 Update rc2
Linux ≫ Linux Kernel Version 2.6.35 Update rc3
Linux ≫ Linux Kernel Version 2.6.35 Update rc4
Linux ≫ Linux Kernel Version 2.6.35 Update rc5
Linux ≫ Linux Kernel Version 2.6.35 Update rc6
Linux ≫ Linux Kernel Version 6.19 Update rc1
Linux ≫ Linux Kernel Version 6.19 Update rc2
Linux ≫ Linux Kernel Version 6.19 Update rc3
Linux ≫ Linux Kernel Version 6.19 Update rc4
Linux ≫ Linux Kernel Version 6.19 Update rc5
Linux ≫ Linux Kernel Version 6.19 Update rc6
Linux ≫ Linux Kernel Version 6.19 Update rc7
Linux ≫ Linux Kernel Version 6.19 Update rc8
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.12% 0.024
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.1 1.8 5.2
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.1 1.8 5.2
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
CWE-125 Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

https://git.kernel.org/stable/c/13336a6239b9d7c6e61483017bb8bdfe3ceb10a5
Patch
https://git.kernel.org/stable/c/e41a23e61259f5526af875c3b86b3d42a9bae0e5
Patch
https://git.kernel.org/stable/c/8a672f177ebe19c93d795fbe967846084fbc7943
Patch
https://git.kernel.org/stable/c/cabd1a976375780dabab888784e356f574bbaed8
Patch
https://git.kernel.org/stable/c/cfa745830e45ecb75c061aa34330ee0cac941cc7
https://cert-portal.siemens.com/productcert/html/ssa-082556.html
https://git.kernel.org/stable/c/29681ed51e737be14d18ecd1c304c57002e4b72c
https://git.kernel.org/stable/c/66e4b63d61c15de6ca5332d9ca6db59a404d7136
https://cert-portal.siemens.com/productcert/html/ssa-019113.html