5.5

CVE-2026-52985

netdevsim: zero initialize struct iphdr in dummy sk_buff

In the Linux kernel, the following vulnerability has been resolved:

netdevsim: zero initialize struct iphdr in dummy sk_buff

Syzbot reports a KMSAN uninit-value originating from
nsim_dev_trap_skb_build, with the allocation also
being performed in the same function.

Fix this by calling skb_put_zero instead of skb_put to
guarantee zero initialization of the whole IP header.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
LinuxLinux Kernel Version >= 5.4 < 5.10.258
LinuxLinux Kernel Version >= 5.11 < 5.15.209
LinuxLinux Kernel Version >= 5.16 < 6.1.175
LinuxLinux Kernel Version >= 6.2 < 6.6.141
LinuxLinux Kernel Version >= 6.7 < 6.12.91
LinuxLinux Kernel Version >= 6.13 < 6.18.33
LinuxLinux Kernel Version >= 6.19 < 7.0.10
LinuxLinux Kernel Version7.1 Updaterc1
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.12% 0.024
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE-908 Use of Uninitialized Resource

The product uses or accesses a resource that has not been initialized.

https://git.kernel.org/stable/c/175556c049eaec14efde8c6475e763b7579b9de7
Patch
https://git.kernel.org/stable/c/6e2cfd0904976e701d7a76b86b694e72af230ab0
Patch
https://git.kernel.org/stable/c/1b7b6ae0e93b8d512e208b1378d74af052e4f4e7
Patch
https://git.kernel.org/stable/c/818f7673ed7f4a29d4b9cee8184c47d6e57162b4
Patch
https://git.kernel.org/stable/c/978ca6ff789f1f19c03288ac20cc1f4774e88490
Patch
https://git.kernel.org/stable/c/750d0091bebf44975421268d37484ef87060d263
Patch
https://git.kernel.org/stable/c/bc6002865e8c4fcf9e94975f7cf023448d8764e2
Patch
https://git.kernel.org/stable/c/35eaa6d8d6c2ee65e96f507add856e0eacf24591
Patch