7.5

CVE-2026-64414

netfilter: handle unreadable frags

In the Linux kernel, the following vulnerability has been resolved:

netfilter: handle unreadable frags

sashiko reports:
 When an skb with unreadable fragments (such as from devmem TCP, where
 skb_frags_readable(skb) returns false) is processed by the u32 module,
 skb_copy_bits() will safely return a negative error code [..]

xt_u32: bail out with hotdrop in this case.
gather_frags: return -1, just as if we had no fragment header.
nfnetlink_queue: restrict to the linear part.
nfnetlink_log: restrict to the linear part.

v2:
 - skb_zerocopy helpers don't copy readable flag, i.e. nfnetlink_queue
 is broken too
 xt_u32 shouldn't return true if hotdrop was set.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version 65249feb6b3df9e17bab5911ee56fa7b0971e231
Version < 3b13e7635795394705920cca1e1db7e4ca2e334b
Status affected
Version 65249feb6b3df9e17bab5911ee56fa7b0971e231
Version < fc5bfe63bacf8a3ae307b62b34206406ca733354
Status affected
Version 65249feb6b3df9e17bab5911ee56fa7b0971e231
Version < 57056be3ec12e7d9ecd20a60d4060f510e4f284c
Status affected
Version 65249feb6b3df9e17bab5911ee56fa7b0971e231
Version < da5b58478a9c1b85608c9e40a3b8432d071b409e
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 6.12
Status affected
Version 0
Version < 6.12
Status unaffected
Version <= 6.12.*
Version 6.12.96
Status unaffected
Version <= 6.18.*
Version 6.18.39
Status unaffected
Version <= 7.1.*
Version 7.1.4
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.44% 0.36
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/3b13e7635795394705920cca1e1db7e4ca2e334b
https://git.kernel.org/stable/c/fc5bfe63bacf8a3ae307b62b34206406ca733354
https://git.kernel.org/stable/c/57056be3ec12e7d9ecd20a60d4060f510e4f284c
https://git.kernel.org/stable/c/da5b58478a9c1b85608c9e40a3b8432d071b409e