PT-2026-106569 · Linux · Linux
CVE-2026-98240
·
Publicado
2026-10-06
·
Atualizado
2026-10-06
Nenhuma
Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
net: ip tunnel: initialize
options len before referencing optionsThe following command triggers a kernel panic:
ip link add d0 type dummy; ip link set d0 up
ip route add 10.30.0.0/16
encap ip id 300 geneve opts 4660:66:11223344 dev d0
memcpy: detected buffer overflow: 4 byte write of buffer size 0
kernel BUG at lib/string helpers.c:1044!
...
ip tun parse opts.part.0.cold+0x10/0x10
ip tun build state+0x116/0x2a0
On kernels built with GCC 15+ and
CONFIG FORTIFY SOURCE, the fortified
memcpy() got 0 sized destination with request of 4 bytes length:static int ip tun parse opts geneve(...)
{
...
attr = tb[LWTUNNEL IP OPT GENEVE DATA];
data len = nla len(attr); /* == 4 */
struct geneve opt opt = ip tunnel info opts(info) + opts len;
memcpy(opt->opt data, nla data(attr), data len);
/ ^^^^^^^^^^^^^ 0 since options len is assigned afterwards */
Fixed by initializing the counter before the options are referenced.
Matching what
tunnel key opts set() already does. Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Linux