7.8
CVE-2026-97612
- EPSS 0.16%
- Veröffentlicht 25.09.2026 10:22:21
- Zuletzt bearbeitet 03.10.2026 11:18:07
- Erkennungen
net: mpls: clear inner_protocol when the last label is popped
In the Linux kernel, the following vulnerability has been resolved:
net: mpls: clear inner_protocol when the last label is popped
skb_mpls_push() records the pre-encapsulation network header once, gated
on !skb->inner_protocol. skb_mpls_pop() never clears that record, so it
outlives the encapsulation it describes.
Open vSwitch can then re-push MPLS onto a packet whose
inner_network_header still points at the older, deeper offset: push a
label, pop every label, recirculate (ovs_flow_key_update() re-derives
key->eth.type and resets network_header, but leaves inner_*), then push
again. ovs_fragment() trusts the record:
skb->network_header = skb->inner_network_header;
so skb_network_offset() goes negative. The bound check is signed:
if (skb_network_offset(skb) > MAX_L2_LEN)
a negative offset passes it, and prepare_frag() widens the value:
unsigned int hlen = skb_network_offset(skb);
memcpy(&data->l2_data, skb->data, hlen);
which is a ~4GiB memcpy out of a 30-byte per-CPU buffer.
Reproduced on v7.3-rc1. RDX is the truncated length, (unsigned int)(-8):
BUG: unable to handle page fault for address: ffffe8ffffc16000
#PF: supervisor write access in kernel mode
Oops: 0002 [#1] SMP KASAN NOPTI
RIP: 0010:memcpy+0x8/0x20
RDX: 00000000fffffff8 RSI: ffff888105d732db RDI: ffffe8ffffc16000
prepare_frag+0x3df/0x4e0
ovs_fragment+0x589/0x7e0
do_output+0x4ce/0x5e0
do_execute_actions+0x55d2/0x7b30
ovs_execute_actions+0xea/0x450
Same root-cause shape as commit 975b5b067f52 ("ipv6: sr: restore network
header before routing and forwarding"): a stale network header offset
reaching a consumer that widens it. Here it originates in the MPLS
push/pop path.
Clear inner_protocol once the packet is no longer MPLS, so a later push
re-records the current header. net/sched/act_mpls.c is the only other
skb_mpls_pop() caller and gets the same fix; sch_frag.c saves and
restores inner_protocol around fragmentation in the same way OVS does.Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
48d2ab609b6bbecb7698487c8579bc40de9d6dfa
Version <
55ed97db27bffe29c21fdefd5d25601322c36ff8
Status
affected
Version
48d2ab609b6bbecb7698487c8579bc40de9d6dfa
Version <
833ec2788322306407503b4cfc7745cd1f9d785f
Status
affected
Version
48d2ab609b6bbecb7698487c8579bc40de9d6dfa
Version <
38db09804b2616aa1e2fcdf97f0c3ae8b9dbdd34
Status
affected
Version
48d2ab609b6bbecb7698487c8579bc40de9d6dfa
Version <
0b3425fd0ecd515997956f7bb8a8a576b444ed64
Status
affected
Version
48d2ab609b6bbecb7698487c8579bc40de9d6dfa
Version <
011e17b5cae19b9f6a150923275e41c278de64f0
Status
affected
Version
48d2ab609b6bbecb7698487c8579bc40de9d6dfa
Version <
da8c3a7f5d3137fec4ff60a6248f5f6d66b6a63e
Status
affected
Version
48d2ab609b6bbecb7698487c8579bc40de9d6dfa
Version <
b39120523475d6b436be7f6cb27d48064148a327
Status
affected
Version
48d2ab609b6bbecb7698487c8579bc40de9d6dfa
Version <
78a86d75a70e1e227711c72865c59b1422d0a5ae
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
4.9
Status
affected
Version
0
Version <
4.9
Status
unaffected
Version <=
5.10.*
Version
5.10.271
Status
unaffected
Version <=
5.15.*
Version
5.15.222
Status
unaffected
Version <=
6.1.*
Version
6.1.189
Status
unaffected
Version <=
6.6.*
Version
6.6.158
Status
unaffected
Version <=
6.12.*
Version
6.12.111
Status
unaffected
Version <=
6.18.*
Version
6.18.53
Status
unaffected
Version <=
7.2.*
Version
7.2.7
Status
unaffected
Version <=
*
Version
7.3-rc3
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.16% | 0.049 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
https://git.kernel.org/stable/c/011e17b5cae19b9f6a150923275e41c278de64f0
https://git.kernel.org/stable/c/da8c3a7f5d3137fec4ff60a6248f5f6d66b6a63e
https://git.kernel.org/stable/c/b39120523475d6b436be7f6cb27d48064148a327
https://git.kernel.org/stable/c/78a86d75a70e1e227711c72865c59b1422d0a5ae
https://git.kernel.org/stable/c/0b3425fd0ecd515997956f7bb8a8a576b444ed64
https://git.kernel.org/stable/c/38db09804b2616aa1e2fcdf97f0c3ae8b9dbdd34
https://git.kernel.org/stable/c/55ed97db27bffe29c21fdefd5d25601322c36ff8
https://git.kernel.org/stable/c/833ec2788322306407503b4cfc7745cd1f9d785f