-

CVE-2026-98095

af_packet: Don't cast tpacket_hdr.tp_len to int in tpacket_parse_header().

In the Linux kernel, the following vulnerability has been resolved:

af_packet: Don't cast tpacket_hdr.tp_len to int in tpacket_parse_header().

syzbot reported BUG() in sock_sendmsg_nosec(). [0]

The problem is that tpacket_parse_header() casts user-provided
tpacket_hdr.tp_len, which is u32, to int.

If the length is larger than INT_MAX, the following condition
in tpacket_parse_header() passes,

  if (unlikely(tp_len > size_max))

and any negative value can be returned to the caller, up to
sock_sendmsg_nosec().

The repro set tpacket_hdr.tp_len to 0xfffffdef, which is cast
to -EIOCBQUEUED (-529), triggering BUG() in sock_sendmsg_nosec().

  *(uint64_t*)0x200000000008 = 0xfffffdef;
  ...
  syscall(__NR_write, /*fd=*/r[0], /*buf=*/0x200000000000ul, /*count=*/1ul);

Let's define the local tp_len as u32 in tpacket_parse_header().

[0]:
kernel BUG at net/socket.c:803!
Oops: invalid opcode: 0000 [#1] SMP KASAN PTI
CPU: 0 UID: 0 PID: 5628 Comm: syz-executor176 Not tainted syzkaller #0 PREEMPT(full)
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 07/24/2026
RIP: 0010:sock_sendmsg_nosec+0x145/0x180 net/socket.c:803
Code: 06 67 48 0f b9 3a eb 95 e8 e8 3a 22 f8 48 89 df 4c 89 f6 4c 89 e2 4d 89 fb 2e e8 32 a5 5c 16 e9 51 ff ff ff e8 cc 3a 22 f8 90 <0f> 0b e8 c4 3a 22 f8 48 83 c3 18 48 89 d8 48 c1 e8 03 42 80 3c 28
RSP: 0018:ffffc90003aefb48 EFLAGS: 00010293
RAX: ffffffff89a578d4 RBX: ffff8880764c67c0 RCX: ffff88807fb23e80
RDX: 0000000000000000 RSI: 00000000fffffdef RDI: 00000000fffffdef
RBP: 00000000fffffdef R08: ffffc90003aef747 R09: 1ffff9200075dee8
R10: dffffc0000000000 R11: fffff5200075dee9 R12: 0000000000000001
R13: dffffc0000000000 R14: ffffc90003aefbc0 R15: ffffffff8aac4310
FS:  000055559101b400(0000) GS:ffff888124ce0000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000200000000210 CR3: 0000000073dca000 CR4: 00000000003526f0
Call Trace:
 <TASK>
 __sock_sendmsg net/socket.c:815 [inline]
 sock_write_iter+0x2de/0x3e0 net/socket.c:1266
 new_sync_write fs/read_write.c:595 [inline]
 vfs_write+0x612/0xba0 fs/read_write.c:687
 ksys_write+0x150/0x270 fs/read_write.c:739
 do_syscall_x64 arch/x86/entry/syscall_64.c:61 [inline]
 do_syscall_64+0x166/0x520 arch/x86/entry/syscall_64.c:84
 entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7f173130ecb9
Code: c0 79 93 eb d5 48 8d 7c 1d 00 eb 99 0f 1f 44 00 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 d8 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007ffd67e44248 EFLAGS: 00000246 ORIG_RAX: 0000000000000001
RAX: ffffffffffffffda RBX: 0000200000000000 RCX: 00007f173130ecb9
RDX: 0000000000000001 RSI: 0000200000000000 RDI: 0000000000000003
RBP: 0000000000000001 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 00007ffd67e44388
R13: 0000000000000002 R14: 00002000000000c0 R15: 0000000000000002
 </TASK>
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 69e3c75f4d541a6eb151b3ef91f34033cb3ad6e1
Version < 3e0cad1432a0c0564f5076bab16f1aa4c0474be4
Status affected
Version 69e3c75f4d541a6eb151b3ef91f34033cb3ad6e1
Version < 6d4d55f75fa0ea32d874eb33e356e9361f3e4591
Status affected
Version 69e3c75f4d541a6eb151b3ef91f34033cb3ad6e1
Version < 09e3c9b32434600a6992e762bf0d6837f5902134
Status affected
Version 69e3c75f4d541a6eb151b3ef91f34033cb3ad6e1
Version < 2b9fa12fbdbfc0f671ff23b0ea06c177a6b8a6b8
Status affected
Version 69e3c75f4d541a6eb151b3ef91f34033cb3ad6e1
Version < c6b3db727876a027013aa4ccb6913a153a2af41a
Status affected
Version 69e3c75f4d541a6eb151b3ef91f34033cb3ad6e1
Version < 72abe77e88c3f1f71c5348124e9b28e285f26950
Status affected
Version 69e3c75f4d541a6eb151b3ef91f34033cb3ad6e1
Version < 9d714076ff398ba8cc5ae0ae146f4a1ea0bbf5e8
Status affected
Version 69e3c75f4d541a6eb151b3ef91f34033cb3ad6e1
Version < 73e594c19b4f815d8343461cec7074c4713bbde7
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 2.6.31
Status affected
Version 0
Version < 2.6.31
Status unaffected
Version <= 5.10.*
Version 5.10.271
Status unaffected
Version <= 5.15.*
Version 5.15.222
Status unaffected
Version <= 6.1.*
Version 6.1.189
Status unaffected
Version <= 6.6.*
Version 6.6.158
Status unaffected
Version <= 6.12.*
Version 6.12.111
Status unaffected
Version <= 6.18.*
Version 6.18.53
Status unaffected
Version <= 7.2.*
Version 7.2.7
Status unaffected
Version <= *
Version 7.3-rc2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.054
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/c6b3db727876a027013aa4ccb6913a153a2af41a
https://git.kernel.org/stable/c/72abe77e88c3f1f71c5348124e9b28e285f26950
https://git.kernel.org/stable/c/9d714076ff398ba8cc5ae0ae146f4a1ea0bbf5e8
https://git.kernel.org/stable/c/73e594c19b4f815d8343461cec7074c4713bbde7
https://git.kernel.org/stable/c/09e3c9b32434600a6992e762bf0d6837f5902134
https://git.kernel.org/stable/c/2b9fa12fbdbfc0f671ff23b0ea06c177a6b8a6b8
https://git.kernel.org/stable/c/3e0cad1432a0c0564f5076bab16f1aa4c0474be4
https://git.kernel.org/stable/c/6d4d55f75fa0ea32d874eb33e356e9361f3e4591