PT-2026-106600 · Linux · Linux
CVE-2026-98271
·
Publicado
2026-10-06
·
Atualizado
2026-10-06
Nenhuma
Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
net: skbuff: do not leave stale header offsets after pskb carve()
pskb carve inside header() and pskb carve inside nonlinear() remove
the first bytes of a packet and reallocate skb->head.
All the headers that were present before the operation are gone,
but both functions call skb headers offset update(skb, 0), which
is a no-op : skb->mac header, skb->network header,
skb->transport header and skb->csum start keep their old values and
now describe bytes which are no longer there.
Both helpers size the new head from the old skb end offset(), so the
stale offsets still land inside the new allocation. They point past
skb tail pointer() though, to bytes that were never initialized.
pskb carve inside nonlinear() is the worst case, because it leaves a
zombie skb with an empty linear part (skb->data ==
skb tail pointer(skb), skb headlen(skb) == 0), while
skb mac header was set() is still true and skb->mac header is way
ahead of skb->data.
The only user of pskb extract() is rds tcp data recv(), and the
carved skb is queued on tinc->ti skb list. When the RDS incoming
message is released, rds tcp inc free() calls skb queue purge(),
which frees the skbs with SKB DROP REASON QUEUE PURGE. This is
visible from drop monitor, which then tries to pull back to the
(bogus) mac header :
skbuff: skb pull(len=234)
skb len=6968 data len=6968 headroom=0 headlen=0 tailroom=0
end-tail=384 mac=(234,14) mac len=14 net=(248,40) trans=288
shinfo(txflags=0 nr frags=1 gso(size=1428 type=16 segs=5))
csum(0x100120 start=288 offset=16 ip summed=3 complete sw=0 valid=1 level=0)
hash(0x7b446c6c sw=0 l4=1) proto=0x86dd pkttype=0 iif=60
kernel BUG at ./include/linux/skbuff.h:2847!
Add skb carve reset headers() to mark the mac and transport headers
as not set, reset the network header, clear skb->mac len, and drop
a now meaningless CHECKSUM PARTIAL (csum start no longer describes
anything).
Invalidate the inner offsets as well. Unlike mac header and
transport header they have no "unset" sentinel, so a leftover
non-zero value still looks like a real header. Zero
skb->inner mac header, skb->inner network header,
skb->inner transport header, skb->inner protocol and
skb->encapsulation, so that all the header state is invalidated in
one place.
v2: fixed an inaccurate changelog. The stale offsets stay inside the
new skb->head, which is never smaller than the old one, they
simply point past skb tail pointer() to bytes that are gone.
Thanks to Xuanqiang Luo for insisting on this.
Also invalidate the inner header state, as suggested by the
netdev AI review :
https://netdev-ai.bots.linux.dev/sashiko/#/patchset/20260911114922.621937-1-edumazet%40google.com
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Linux