7.8

CVE-2026-97612

net: mpls: clear inner_protocol when the last label is popped

In the Linux kernel, the following vulnerability has been resolved:

net: mpls: clear inner_protocol when the last label is popped

skb_mpls_push() records the pre-encapsulation network header once, gated
on !skb->inner_protocol. skb_mpls_pop() never clears that record, so it
outlives the encapsulation it describes.

Open vSwitch can then re-push MPLS onto a packet whose
inner_network_header still points at the older, deeper offset: push a
label, pop every label, recirculate (ovs_flow_key_update() re-derives
key->eth.type and resets network_header, but leaves inner_*), then push
again. ovs_fragment() trusts the record:

	skb->network_header = skb->inner_network_header;

so skb_network_offset() goes negative. The bound check is signed:

	if (skb_network_offset(skb) > MAX_L2_LEN)

a negative offset passes it, and prepare_frag() widens the value:

	unsigned int hlen = skb_network_offset(skb);
	memcpy(&data->l2_data, skb->data, hlen);

which is a ~4GiB memcpy out of a 30-byte per-CPU buffer.

Reproduced on v7.3-rc1. RDX is the truncated length, (unsigned int)(-8):

  BUG: unable to handle page fault for address: ffffe8ffffc16000
  #PF: supervisor write access in kernel mode
  Oops: 0002 [#1] SMP KASAN NOPTI
  RIP: 0010:memcpy+0x8/0x20
  RDX: 00000000fffffff8 RSI: ffff888105d732db RDI: ffffe8ffffc16000
   prepare_frag+0x3df/0x4e0
   ovs_fragment+0x589/0x7e0
   do_output+0x4ce/0x5e0
   do_execute_actions+0x55d2/0x7b30
   ovs_execute_actions+0xea/0x450

Same root-cause shape as commit 975b5b067f52 ("ipv6: sr: restore network
header before routing and forwarding"): a stale network header offset
reaching a consumer that widens it. Here it originates in the MPLS
push/pop path.

Clear inner_protocol once the packet is no longer MPLS, so a later push
re-records the current header. net/sched/act_mpls.c is the only other
skb_mpls_pop() caller and gets the same fix; sch_frag.c saves and
restores inner_protocol around fragmentation in the same way OVS does.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 48d2ab609b6bbecb7698487c8579bc40de9d6dfa
Version < 55ed97db27bffe29c21fdefd5d25601322c36ff8
Status affected
Version 48d2ab609b6bbecb7698487c8579bc40de9d6dfa
Version < 833ec2788322306407503b4cfc7745cd1f9d785f
Status affected
Version 48d2ab609b6bbecb7698487c8579bc40de9d6dfa
Version < 38db09804b2616aa1e2fcdf97f0c3ae8b9dbdd34
Status affected
Version 48d2ab609b6bbecb7698487c8579bc40de9d6dfa
Version < 0b3425fd0ecd515997956f7bb8a8a576b444ed64
Status affected
Version 48d2ab609b6bbecb7698487c8579bc40de9d6dfa
Version < 011e17b5cae19b9f6a150923275e41c278de64f0
Status affected
Version 48d2ab609b6bbecb7698487c8579bc40de9d6dfa
Version < da8c3a7f5d3137fec4ff60a6248f5f6d66b6a63e
Status affected
Version 48d2ab609b6bbecb7698487c8579bc40de9d6dfa
Version < b39120523475d6b436be7f6cb27d48064148a327
Status affected
Version 48d2ab609b6bbecb7698487c8579bc40de9d6dfa
Version < 78a86d75a70e1e227711c72865c59b1422d0a5ae
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 4.9
Status affected
Version 0
Version < 4.9
Status unaffected
Version <= 5.10.*
Version 5.10.271
Status unaffected
Version <= 5.15.*
Version 5.15.222
Status unaffected
Version <= 6.1.*
Version 6.1.189
Status unaffected
Version <= 6.6.*
Version 6.6.158
Status unaffected
Version <= 6.12.*
Version 6.12.111
Status unaffected
Version <= 6.18.*
Version 6.18.53
Status unaffected
Version <= 7.2.*
Version 7.2.7
Status unaffected
Version <= *
Version 7.3-rc3
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.16% 0.049
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/011e17b5cae19b9f6a150923275e41c278de64f0
https://git.kernel.org/stable/c/da8c3a7f5d3137fec4ff60a6248f5f6d66b6a63e
https://git.kernel.org/stable/c/b39120523475d6b436be7f6cb27d48064148a327
https://git.kernel.org/stable/c/78a86d75a70e1e227711c72865c59b1422d0a5ae
https://git.kernel.org/stable/c/0b3425fd0ecd515997956f7bb8a8a576b444ed64
https://git.kernel.org/stable/c/38db09804b2616aa1e2fcdf97f0c3ae8b9dbdd34
https://git.kernel.org/stable/c/55ed97db27bffe29c21fdefd5d25601322c36ff8
https://git.kernel.org/stable/c/833ec2788322306407503b4cfc7745cd1f9d785f