PT-2026-106600 · Linux · Linux

CVE-2026-98271

·

Published

2026-10-06

·

Updated

2026-10-06

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
net: skbuff: do not leave stale header offsets after pskb carve()
pskb carve inside header() and pskb carve inside nonlinear() remove the first bytes of a packet and reallocate skb->head.
All the headers that were present before the operation are gone, but both functions call skb headers offset update(skb, 0), which is a no-op : skb->mac header, skb->network header, skb->transport header and skb->csum start keep their old values and now describe bytes which are no longer there.
Both helpers size the new head from the old skb end offset(), so the stale offsets still land inside the new allocation. They point past skb tail pointer() though, to bytes that were never initialized.
pskb carve inside nonlinear() is the worst case, because it leaves a zombie skb with an empty linear part (skb->data == skb tail pointer(skb), skb headlen(skb) == 0), while skb mac header was set() is still true and skb->mac header is way ahead of skb->data.
The only user of pskb extract() is rds tcp data recv(), and the carved skb is queued on tinc->ti skb list. When the RDS incoming message is released, rds tcp inc free() calls skb queue purge(), which frees the skbs with SKB DROP REASON QUEUE PURGE. This is visible from drop monitor, which then tries to pull back to the (bogus) mac header :
skbuff: skb pull(len=234) skb len=6968 data len=6968 headroom=0 headlen=0 tailroom=0 end-tail=384 mac=(234,14) mac len=14 net=(248,40) trans=288 shinfo(txflags=0 nr frags=1 gso(size=1428 type=16 segs=5)) csum(0x100120 start=288 offset=16 ip summed=3 complete sw=0 valid=1 level=0) hash(0x7b446c6c sw=0 l4=1) proto=0x86dd pkttype=0 iif=60 kernel BUG at ./include/linux/skbuff.h:2847!
Add skb carve reset headers() to mark the mac and transport headers as not set, reset the network header, clear skb->mac len, and drop a now meaningless CHECKSUM PARTIAL (csum start no longer describes anything).
Invalidate the inner offsets as well. Unlike mac header and transport header they have no "unset" sentinel, so a leftover non-zero value still looks like a real header. Zero skb->inner mac header, skb->inner network header, skb->inner transport header, skb->inner protocol and skb->encapsulation, so that all the header state is invalidated in one place.
v2: fixed an inaccurate changelog. The stale offsets stay inside the new skb->head, which is never smaller than the old one, they simply point past skb tail pointer() to bytes that are gone. Thanks to Xuanqiang Luo for insisting on this. Also invalidate the inner header state, as suggested by the netdev AI review : https://netdev-ai.bots.linux.dev/sashiko/#/patchset/20260911114922.621937-1-edumazet%40google.com
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-98271

Affected Products

Linux