PT-2026-90279 · Linux · Linux
CVE-2026-89563
·
Publicado
2026-09-11
·
Atualizado
2026-09-12
Nenhuma
Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
ip6 tunnel: use skb cow head() in ip6 tnl xmit()
ip6 tnl xmit() may need to expand headroom before it can push the
outer IPv6 and optional encap headers. It currently does that with
skb realloc headroom(), copies skb->sk ownership, consumes the original
skb, and then continues processing with the replacement skb kept only in
its local variable.
That is safe only if the helper cannot fail afterwards. But this helper
still has post-reallocation error exits. collect md tunnels reject
non-NONE encap after the replacement, and ip6 tnl encap() can also fail
later. In those cases the helper returns an error to its callers while
the caller still only has the original skb pointer.
Both ip6 tnl start xmit() and the IPv6 GRE paths free the caller skb on
error, so they can end up freeing an skb that ip6 tnl xmit() already
consumed.
Use skb cow head() instead. It provides the required headroom and
writability without privately replacing the caller-owned skb, so later
error returns cannot leave callers with a stale pointer.
The Ethernet users, ip6gretap and ip6erspan, clear IFF TX SKB SHARING
and already call skb cow head() before entering ip6 tnl xmit(). They do
not rely on the removed skb shared() reallocation. This also makes the
IPv6 tunnel path consistent with ip tunnel xmit().
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Linux