PT-2026-98629 · Linux · Linux

CVE-2026-97965

·

Publicado

2026-09-25

·

Atualizado

2026-09-25

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
vxlan: initialize md in vxlan xmit one()
If a VXLAN device is configured with both VXLAN F COLLECT METADATA and VXLAN F GBP, and a packet is transmitted through it using an external ip tunnel info that lacks the IP TUNNEL VXLAN OPT BIT flag, md is left pointing to the uninitialized md stack variable:
    if (test bit(IP TUNNEL VXLAN OPT BIT, info->key.tun flags)) {
        if (info->options len < sizeof(*md))
            goto drop;
        md = ip tunnel info opts(info);
    }
Because IP TUNNEL VXLAN OPT BIT is not set, md is not updated and remains pointing to md. Later, vxlan build skb() is called with md, which eventually calls vxlan build gbp hdr():
if (vxflags & VXLAN F GBP)
    vxlan build gbp hdr(vxh, md);
Inside vxlan build gbp hdr(), md->gbp is read:
if (!md->gbp)
    return;
gbp = (struct vxlanhdr gbp *)vxh;
...
if (md->gbp & VXLAN GBP DONT LEARN)
    gbp->dont learn = 1;
If the stack contains garbage, this causes:
  1. VXLAN HF GBP flag to be spuriously set in the VXLAN header.
  2. gbp->dont learn and gbp->policy applied to be set from stack bits.
  3. gbp->policy id to receive 16 bits of uninitialized kernel stack data, leaking it onto the wire.
Fix this by zero-initializing md. If IP TUNNEL VXLAN OPT BIT is not present, md->gbp remains 0, and vxlan build gbp hdr() returns early without modifying the VXLAN header.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2026-97965

Produtos afetados

Linux