9.8

CVE-2026-64007

netfilter: synproxy: refresh tcphdr after skb_ensure_writable

In the Linux kernel, the following vulnerability has been resolved:

netfilter: synproxy: refresh tcphdr after skb_ensure_writable

synproxy_tstamp_adjust() rewrites the TCP timestamp option in place
and then patches the TCP checksum via inet_proto_csum_replace4() on
the caller-supplied tcphdr pointer.  Both ipv4_synproxy_hook() and
ipv6_synproxy_hook() obtain that pointer with skb_header_pointer()
before calling in, so it may either alias skb->head directly or
point at the caller's on-stack _tcph buffer.

Between obtaining the pointer and using it, the function calls
skb_ensure_writable(skb, optend), which on a cloned or non-linear
skb invokes pskb_expand_head() and frees the old skb->head.  After
that point the cached th is stale:

    caller (ipv[46]_synproxy_hook)
      th = skb_header_pointer(skb, ..., &_tcph)
      synproxy_tstamp_adjust(skb, protoff, th, ...)
        skb_ensure_writable(skb, optend)
          pskb_expand_head()        /* kfree(old skb->head) */
        ...
        inet_proto_csum_replace4(&th->check, ...)
                                    /* writes into freed head, or
                                       into the caller's stack copy
                                       leaving the on-wire checksum
                                       stale */

The option bytes are written through skb->data and are fine; only
the checksum update goes through th and so lands in the wrong
place.  The result is either a write into freed slab memory or a
packet leaving with a checksum that does not match its payload.

Fix by re-deriving th from skb->data + protoff immediately after
skb_ensure_writable() succeeds, so the subsequent checksum update
targets the linear, writable header.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version 48b1de4c110a7afa4b85862f6c75af817db26fad
Version < 9902a1058992de5d95656b64a3bd95c077f7ba2c
Status affected
Version 48b1de4c110a7afa4b85862f6c75af817db26fad
Version < d3019c61799adc21811af4b521f11f3dc77f8e04
Status affected
Version 48b1de4c110a7afa4b85862f6c75af817db26fad
Version < dd206819f210522579010d889d45a9530bb494bc
Status affected
Version 48b1de4c110a7afa4b85862f6c75af817db26fad
Version < af2c22ccb1f621aff487ff47a040e38e058541e7
Status affected
Version 48b1de4c110a7afa4b85862f6c75af817db26fad
Version < c7f945f7da097245a2f8ed7775ce48421047ee96
Status affected
Version 48b1de4c110a7afa4b85862f6c75af817db26fad
Version < f0fea2b6d5453a11ad11713bbf37561b9b3a7edf
Status affected
Version 48b1de4c110a7afa4b85862f6c75af817db26fad
Version < a91887a5b6ee4b98dfbf1db657ed2b879430149e
Status affected
Version 48b1de4c110a7afa4b85862f6c75af817db26fad
Version < 92170e6afe927ab2792a3f71902845789c8e31b1
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 3.12
Status affected
Version 0
Version < 3.12
Status unaffected
Version <= 5.10.*
Version 5.10.259
Status unaffected
Version <= 5.15.*
Version 5.15.210
Status unaffected
Version <= 6.1.*
Version 6.1.176
Status unaffected
Version <= 6.6.*
Version 6.6.143
Status unaffected
Version <= 6.12.*
Version 6.12.93
Status unaffected
Version <= 6.18.*
Version 6.18.35
Status unaffected
Version <= 7.0.*
Version 7.0.12
Status unaffected
Version <= *
Version 7.1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.51% 0.407
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/9902a1058992de5d95656b64a3bd95c077f7ba2c
https://git.kernel.org/stable/c/d3019c61799adc21811af4b521f11f3dc77f8e04
https://git.kernel.org/stable/c/dd206819f210522579010d889d45a9530bb494bc
https://git.kernel.org/stable/c/af2c22ccb1f621aff487ff47a040e38e058541e7
https://git.kernel.org/stable/c/c7f945f7da097245a2f8ed7775ce48421047ee96
https://git.kernel.org/stable/c/f0fea2b6d5453a11ad11713bbf37561b9b3a7edf
https://git.kernel.org/stable/c/a91887a5b6ee4b98dfbf1db657ed2b879430149e
https://git.kernel.org/stable/c/92170e6afe927ab2792a3f71902845789c8e31b1