8.6

CVE-2026-80590

inet: frags: strip GSO state from fragments before reassembly

In the Linux kernel, the following vulnerability has been resolved:

inet: frags: strip GSO state from fragments before reassembly

A virtio_net_hdr (tun/tap, or AF_PACKET with PACKET_VNET_HDR) can mark
an IPv4 or IPv6 fragment as GSO; nothing relates gso_type to frag_off.
inet_frag_reasm_prepare()/inet_frag_reasm_finish() keep the first
fragment's skb as the head of the reassembled datagram, including its
shinfo->gso_size/gso_type/gso_segs, and chain the remaining fragments
on frag_list with whatever linear/paged layout they arrived with.

After ip_defrag() (ip_local_deliver(), nf_defrag_ipv4, ...) the
reassembled skb therefore still claims to be GSO (SKB_GSO_DODGY), and
the next software segmentation point - udp_rcv_segment() on local
delivery, validate_xmit_skb(), or the ip_finish_output_gso() slow
path - hands it to skb_segment(). skb_segment()'s frag_list walk
assumes GRO-shaped input and hits one of its BUG_ON()s. Two writes to
a tap by an unprivileged user in its own userns are enough:

  kernel BUG at net/core/skbuff.c:4899!
  Oops: invalid opcode: 0000 [#1] SMP KASAN NOPTI
  CPU: 0 UID: 1000 PID: 82 Comm: poc Not tainted 7.2.0-pentest+ #2
  RIP: 0010:skb_segment+0x20ca/0x48b0
  Call Trace:
   <TASK>
   __udp_gso_segment+0x29a/0x27d0
   udp4_ufo_fragment+0x458/0x6c0
   inet_gso_segment+0x429/0x1340
   skb_mac_gso_segment+0x233/0x4f0
   __skb_gso_segment+0x308/0x660
   udp_queue_rcv_skb+0x440/0xad0
   udp_unicast_rcv_skb+0xc7/0x2c0
   udp_rcv+0x16ce/0x2260
   ip_protocol_deliver_rcu+0x197/0x2d0
   ip_local_deliver+0x430/0x690
   ip_rcv+0x16f/0x1f0
   __netif_receive_skb_one_core+0x15e/0x1c0
   __netif_receive_skb+0x1e/0x110
   netif_receive_skb+0xf6/0x5c0
   tun_rx_batched.isra.0+0x3ab/0x790
   tun_get_user+0x17c3/0x3550
   tun_chr_write_iter+0xba/0x1b0
   vfs_write+0x646/0x1130
   </TASK>
  Kernel panic - not syncing: Fatal exception in interrupt

This runs with BH disabled, so it is a panic rather than an oops. The
same is reachable with CAP_NET_RAW in a netns where a defrag point
precedes a GSO point, and from a guest whose VMM forwards
virtio_net_hdr to a tap. The SKB_GSO_DODGY frag_list checks added by
commit 3dcbdb134f32 ("net: gso: Fix skb_segment splat when splitting
gso_size mangled skb having linear-headed frag_list") and by
commit 9e4b7a99a03a ("net: gso: fix panic on frag_list with mixed head
alloc types") do not cover it: page-backed heads skip them, and kmalloc
heads skip them when gso_size == skb_headlen(head), which the sender
controls.

An skb entering a frag queue is an IP fragment by definition and
cannot legitimately carry GSO state: GRO does not merge fragments and
the stack segments before it fragments, so only untrusted sources are
affected. This has been reachable since
commit f43798c27684 ("tun: Allow GSO using virtio_net_hdr"), the first
path that let userspace attach GSO metadata to an IP fragment. Reset
the GSO fields of every fragment as it is queued, in
inet_frag_queue_insert(), which IPv4, IPv6, nf_conntrack_reasm and
6lowpan reassembly share; then neither the head nor the frag_list
members of the reassembled skb carry them (the members matter too:
the ip_do_fragment()/ip6_fragment() fast paths send them out as they
are). The head may remain CHECKSUM_PARTIAL; that is already accepted
on receive and resolved by skb_checksum_help() in
ip_do_fragment()/ip6_fragment() on forward.

Tested on top of net.git (dc4b95b8fee9), x86_64: the tap reproducer
above, two further IPv4 frag_list geometries that reach
BUG_ON(i >= nfrags) and BUG_ON(!list_skb->head_frag), and an IPv6
fragment-header variant (udp6_ufo_fragment()) each panic the unpatched
kernel; with this patch all four datagrams are delivered intact and
nothing is logged.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version f43798c27684ab925adde7d8acc34c78c6e50df8
Version < cfdbc8c2e6f9ef5d8b8e54859da03dfe682b0bee
Status affected
Version f43798c27684ab925adde7d8acc34c78c6e50df8
Version < 29dda278a5ed272f2230ff4eaa23cf403107bba0
Status affected
Version f43798c27684ab925adde7d8acc34c78c6e50df8
Version < 14a8f3e10fa9a5abd6cedcdaa0c0b7ea9a09f234
Status affected
Version f43798c27684ab925adde7d8acc34c78c6e50df8
Version < 3edf721bb4b99d272c336631b44e3d8ff9a4f31b
Status affected
Version f43798c27684ab925adde7d8acc34c78c6e50df8
Version < dec2edb7aaf12a8878b3a03172ea8fc277b8eaad
Status affected
Version f43798c27684ab925adde7d8acc34c78c6e50df8
Version < c49f04e8d2b94dbb8d9fd99731dd3f00589c8ace
Status affected
Version f43798c27684ab925adde7d8acc34c78c6e50df8
Version < 69b73b74d9eb45f5560a8fe4fa406ada580e1340
Status affected
Version f43798c27684ab925adde7d8acc34c78c6e50df8
Version < da857e448322a2e871ce3ecc2900027041160d43
Status affected
Version f43798c27684ab925adde7d8acc34c78c6e50df8
Version < d5dc1e69fd7258ea605c9952e5d5947539159ae3
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 2.6.27
Status affected
Version 0
Version < 2.6.27
Status unaffected
Version <= 5.10.*
Version 5.10.268
Status unaffected
Version <= 5.15.*
Version 5.15.219
Status unaffected
Version <= 6.1.*
Version 6.1.186
Status unaffected
Version <= 6.6.*
Version 6.6.155
Status unaffected
Version <= 6.12.*
Version 6.12.107
Status unaffected
Version <= 6.18.*
Version 6.18.48
Status unaffected
Version <= 7.1.*
Version 7.1.12
Status unaffected
Version <= 7.2.*
Version 7.2.2
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.51% 0.412
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 8.6 3.9 4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/cfdbc8c2e6f9ef5d8b8e54859da03dfe682b0bee
https://git.kernel.org/stable/c/29dda278a5ed272f2230ff4eaa23cf403107bba0
https://git.kernel.org/stable/c/14a8f3e10fa9a5abd6cedcdaa0c0b7ea9a09f234
https://git.kernel.org/stable/c/3edf721bb4b99d272c336631b44e3d8ff9a4f31b
https://git.kernel.org/stable/c/dec2edb7aaf12a8878b3a03172ea8fc277b8eaad
https://git.kernel.org/stable/c/c49f04e8d2b94dbb8d9fd99731dd3f00589c8ace
https://git.kernel.org/stable/c/69b73b74d9eb45f5560a8fe4fa406ada580e1340
https://git.kernel.org/stable/c/da857e448322a2e871ce3ecc2900027041160d43
https://git.kernel.org/stable/c/d5dc1e69fd7258ea605c9952e5d5947539159ae3