PT-2026-98752 · Linux · Linux
CVE-2026-98089
·
Publicado
2026-09-25
·
Atualizado
2026-09-25
Nenhuma
Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
bonding: alb: fix uninitialized transport header access in alb determine nd()
alb determine nd() uses icmp6 hdr(skb) to inspect ICMPv6 headers.
However, in xmit paths (e.g. packets sent via AF PACKET / raw sockets
or forwarded packets), skb->transport header is not guaranteed to be
initialized. While pskb network may pull() ensures the packet data is
linear starting from the network header, it does not set or adjust the
transport header offset.
Dereferencing icmp6 hdr(skb) can therefore access out-of-bounds memory.
Fetch the icmp6hdr directly after ipv6hdr following pskb network may pull(),
and reload ipv6hdr in case pskb may pull() reallocated skb->head.
Also remove the unused bond argument from alb determine nd().
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Linux