7.3

CVE-2026-72019

macsec: don't read an unset MAC header in macsec_encrypt()

In the Linux kernel, the following vulnerability has been resolved:

macsec: don't read an unset MAC header in macsec_encrypt()

macsec_encrypt() reads the Ethernet header via eth_hdr(skb)
(skb->head + skb->mac_header) to memmove() the 12 source/destination MAC
bytes forward and make room for the SecTAG.

On the AF_PACKET SOCK_RAW + PACKET_QDISC_BYPASS transmit path the skb
reaches the macsec ndo_start_xmit() with the MAC header unset, so
eth_hdr(skb) resolves to skb->head + (u16)~0 and the read is out of
bounds: a 12-byte heap over-read that is also emitted on the wire as the
frame's outer source/destination MAC. KASAN reports a slab-out-of-bounds
read in macsec_start_xmit() on 6.0; on current mainline a CONFIG_DEBUG_NET
build flags it as an unset mac header in skb_mac_header().

On the TX path the L2 header is at skb->data, so use skb_eth_hdr(), added
by commit 96cc4b69581d ("macvlan: do not assume mac_header is set in
macvlan_broadcast()") for exactly this purpose.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version c09440f7dcb304002dfced8c0fea289eb25f2da0
Version < b6cec6187b8632423cd99a94fd5e5ba165fa2a33
Status affected
Version c09440f7dcb304002dfced8c0fea289eb25f2da0
Version < 3adea1b1c04b57e08a5c12a1f42483760581ce61
Status affected
Version c09440f7dcb304002dfced8c0fea289eb25f2da0
Version < dc9ffa1905e72f026d080880a2e4cfc42aa91000
Status affected
Version c09440f7dcb304002dfced8c0fea289eb25f2da0
Version < f21fa533a3ed15ada74106aac4b9ddd078fc6b7a
Status affected
Version c09440f7dcb304002dfced8c0fea289eb25f2da0
Version < e17a42199824973cd8212e95b21ffadf4114a21b
Status affected
Version c09440f7dcb304002dfced8c0fea289eb25f2da0
Version < 2cf10d042562283ff4ae97c02d0993d4f1b5ea29
Status affected
Version c09440f7dcb304002dfced8c0fea289eb25f2da0
Version < c39087ad0b97fc11a3b058dfc8db9fd370762cb9
Status affected
Version c09440f7dcb304002dfced8c0fea289eb25f2da0
Version < f5089008f90c0a7c5520dff3934e0af00adf322d
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 4.6
Status affected
Version 0
Version < 4.6
Status unaffected
Version <= 5.10.*
Version 5.10.265
Status unaffected
Version <= 5.15.*
Version 5.15.216
Status unaffected
Version <= 6.1.*
Version 6.1.178
Status unaffected
Version <= 6.6.*
Version 6.6.145
Status unaffected
Version <= 6.12.*
Version 6.12.97
Status unaffected
Version <= 6.18.*
Version 6.18.40
Status unaffected
Version <= 7.1.*
Version 7.1.5
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.064
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.3 1.8 5.5
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/dc9ffa1905e72f026d080880a2e4cfc42aa91000
https://git.kernel.org/stable/c/f21fa533a3ed15ada74106aac4b9ddd078fc6b7a
https://git.kernel.org/stable/c/e17a42199824973cd8212e95b21ffadf4114a21b
https://git.kernel.org/stable/c/2cf10d042562283ff4ae97c02d0993d4f1b5ea29
https://git.kernel.org/stable/c/c39087ad0b97fc11a3b058dfc8db9fd370762cb9
https://git.kernel.org/stable/c/f5089008f90c0a7c5520dff3934e0af00adf322d
https://git.kernel.org/stable/c/3adea1b1c04b57e08a5c12a1f42483760581ce61
https://git.kernel.org/stable/c/b6cec6187b8632423cd99a94fd5e5ba165fa2a33