PT-2026-98629 · Linux · Linux
CVE-2026-97965
·
Publicado
2026-09-25
·
Atualizado
2026-09-25
Nenhuma
Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
vxlan: initialize md in vxlan xmit one()
If a VXLAN device is configured with both VXLAN F COLLECT METADATA and
VXLAN F GBP, and a packet is transmitted through it using an external
ip tunnel info that lacks the IP TUNNEL VXLAN OPT BIT flag, md is left
pointing to the uninitialized md stack variable:
if (test bit(IP TUNNEL VXLAN OPT BIT, info->key.tun flags)) {
if (info->options len < sizeof(*md))
goto drop;
md = ip tunnel info opts(info);
}Because IP TUNNEL VXLAN OPT BIT is not set, md is not updated and remains
pointing to md. Later, vxlan build skb() is called with md, which
eventually calls vxlan build gbp hdr():
if (vxflags & VXLAN F GBP)
vxlan build gbp hdr(vxh, md);Inside vxlan build gbp hdr(), md->gbp is read:
if (!md->gbp)
return;
gbp = (struct vxlanhdr gbp *)vxh;
...
if (md->gbp & VXLAN GBP DONT LEARN)
gbp->dont learn = 1;If the stack contains garbage, this causes:
- VXLAN HF GBP flag to be spuriously set in the VXLAN header.
- gbp->dont learn and gbp->policy applied to be set from stack bits.
- gbp->policy id to receive 16 bits of uninitialized kernel stack data, leaking it onto the wire.
Fix this by zero-initializing md. If IP TUNNEL VXLAN OPT BIT is not
present, md->gbp remains 0, and vxlan build gbp hdr() returns early
without modifying the VXLAN header.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Linux