-

CVE-2026-98158

ppp_async: drop the errored frame instead of resetting its headroom

In the Linux kernel, the following vulnerability has been resolved:

ppp_async: drop the errored frame instead of resetting its headroom

ppp_receive_nonmp_frame() prepends a two-byte direction tag before running
the pass/active BPF filters:

	*(__be16 *)skb_push(skb, 2) = htons(PPP_FILTER_INBOUND_TAG);

Nothing on the receive path guarantees those two bytes of headroom. The
frame-error path in ppp_async's process_input_packet() resets a reused skb's
headroom to zero while claiming to restore it to a freshly allocated state -
but a fresh skb from dev_alloc_skb() carries NET_SKB_PAD:

	err:
		if (skb) {
			/* make skb appear as freshly allocated */
			skb_trim(skb, 0);
			skb_reserve(skb, - skb_headroom(skb));
		}

ap->rpkt still points at that skb, so the next frame is reassembled into it
with no headroom at all. A peer that sends a bad-FCS frame followed by one
beginning ff 03 then leaves a single byte of headroom by the time the filter
tag is pushed, which lands one byte below skb->head:

  skbuff: skb_under_panic: len:49 put:2 head:ffff888003c10000
          data:ffff888003c0ffff tail:0x30 end:0x640 dev:<NULL>
  kernel BUG at net/core/skbuff.c:214!
  RIP: 0010:skb_panic+0x13e/0x230
  Call Trace:
   skb_push+0xbd/0x100
   ppp_receive_nonmp_frame+0x48a/0x1d10
   ppp_input+0x4e9/0x2f80
   ppp_async_process+0x2a/0xe0
   tasklet_action_common+0x20f/0x8a0
   handle_softirqs+0x18e/0x590
  Kernel panic - not syncing: Fatal exception in interrupt

Zeroing the headroom violates the NET_SKB_PAD guarantee that dev_alloc_skb()
gives the rest of the receive path. Besides the filter panic above, when CCP
compression is enabled ppp_decompress_frame() hands skb->data - 2 to
->decompress()/->incomp(), which then reads out of bounds before skb->head
for the same reason.

Rather than restore the headroom, drop the errored frame - as ppp_synctty
already does on its error path - and clear ap->rpkt so the next frame is
reassembled into a fresh skb with proper headroom. This is simpler and fixes
both the filter under-panic and the CCP out-of-bounds read.

The original V1 of this patch made room in ppp_receive_nonmp_frame() with
skb_cow_head(); Eric pointed out that fixing the root cause in the transport
is the right approach.

Found by fuzzing the PPP receive path with a mutating peer on a pty; it is an
interesting (remote) DoS: root configures PPP, the peer supplies two crashing
frames. The reproducer (repro-ppp-skb.c, unchanged from v1) panics in about a
second, and returns cleanly with this applied.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 6722e78c90054101e6797d5944cdc81af9897a0a
Version < 25f354c55b8435d1f51b8a0a05a3cfe429358523
Status affected
Version 6722e78c90054101e6797d5944cdc81af9897a0a
Version < a86a17745c3e1c6fadd4d6e90c03552dfe531c8c
Status affected
Version 6722e78c90054101e6797d5944cdc81af9897a0a
Version < ff035780adb0f49dc2c7ada26b4697849a68bec8
Status affected
Version 6722e78c90054101e6797d5944cdc81af9897a0a
Version < c4bb894362d224b699e2f95c6c26707d9654e4a3
Status affected
Version 6722e78c90054101e6797d5944cdc81af9897a0a
Version < d0fc3dabfe67caf084e7119ceb2ee23f5ad2f2da
Status affected
Version 6722e78c90054101e6797d5944cdc81af9897a0a
Version < 0c53eb14975f029abd6b26896a460f0d2aaefe6b
Status affected
Version 6722e78c90054101e6797d5944cdc81af9897a0a
Version < 717137221c7d90e7c98bda9a370c9da6cbf015e5
Status affected
Version 6722e78c90054101e6797d5944cdc81af9897a0a
Version < 8dc5d98a16fa23c00999aecf10018c9f69fa5bf4
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 2.6.15
Status affected
Version 0
Version < 2.6.15
Status unaffected
Version <= 5.10.*
Version 5.10.271
Status unaffected
Version <= 5.15.*
Version 5.15.222
Status unaffected
Version <= 6.1.*
Version 6.1.189
Status unaffected
Version <= 6.6.*
Version 6.6.158
Status unaffected
Version <= 6.12.*
Version 6.12.111
Status unaffected
Version <= 6.18.*
Version 6.18.53
Status unaffected
Version <= 7.2.*
Version 7.2.7
Status unaffected
Version <= *
Version 7.3-rc3
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.16% 0.041
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/d0fc3dabfe67caf084e7119ceb2ee23f5ad2f2da
https://git.kernel.org/stable/c/0c53eb14975f029abd6b26896a460f0d2aaefe6b
https://git.kernel.org/stable/c/717137221c7d90e7c98bda9a370c9da6cbf015e5
https://git.kernel.org/stable/c/8dc5d98a16fa23c00999aecf10018c9f69fa5bf4
https://git.kernel.org/stable/c/25f354c55b8435d1f51b8a0a05a3cfe429358523
https://git.kernel.org/stable/c/a86a17745c3e1c6fadd4d6e90c03552dfe531c8c
https://git.kernel.org/stable/c/c4bb894362d224b699e2f95c6c26707d9654e4a3
https://git.kernel.org/stable/c/ff035780adb0f49dc2c7ada26b4697849a68bec8