PT-2026-85718 · Linux · Linux
CVE-2026-80840
·
Published
2026-09-04
·
Updated
2026-09-04
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
ipv6: seg6: clear IPv4 control block on IPIP decapsulation
End.DX4 and End.DT4 decapsulate an IPv4 packet through
decap and validate() and send it directly to IPv4 routing. The inner
packet therefore bypasses ip rcv core(), which normally clears IPCB
before IPv4 interprets skb->cb.
The skb instead retains IP6CB data from the outer packet. IP6CB and
IPCB use the same skb->cb storage, so IP6CB(skb)->lastopt overlaps
IPCB(skb)->opt.optlen and srr, while IP6CB(skb)->nhoff overlaps rr and
ts.
The sender can make the stale optlen byte nonzero with a valid outer
extension-header chain. The reproducers put an eight-byte Destination
Options header immediately after the 40-byte IPv6 header and before the
Segment Routing Header. ipv6 destopt rcv() records the sender-controlled
Destination Options offset in both lastopt and nhoff, setting them to
40. On the reproduced little-endian x86-64 kernel, IPv4 therefore sees
optlen = 40 and rr = 40.
Both tcp v4 save options() and ip options echo() skip option copying
when optlen is zero. Here optlen is 40, so the TCP SYN path allocates
room for 40 bytes of option data and calls ip options echo(). The
stale rr value makes that function read inner packet byte 41 as the
Record Route option length. The reproducers set that sender-controlled
byte to 255, so ip options echo() copies 255 bytes into the 40-byte
option-data area.
Separate End.DX4 and End.DT4 reproducers on the unpatched v7.2-rc5
kernel both produced:
BUG: KASAN: slab-out-of-bounds in ip options echo()
Write of size 255
The relevant End.DX4 call path is:
ip options echo
tcp v4 route req
tcp conn request
tcp v4 conn request
tcp rcv state process
tcp v4 do rcv
tcp v4 rcv
ip protocol deliver rcu
ip local deliver finish
ip local deliver
input action end dx4 finish
input action end dx4
The relevant End.DT4 call path is:
ip options echo
tcp v4 route req
tcp conn request
tcp v4 conn request
tcp rcv state process
tcp v4 do rcv
tcp v4 rcv
ip protocol deliver rcu
ip local deliver finish
ip local deliver
input action end dt4
tcp v4 save options() is inlined into the tcp v4 route req() path, so
it does not appear as a separate frame.
When decap and validate() handles IPPROTO IPIP, save the ingress
interface from IP6CB, clear IPCB, and restore the saved value. Doing
this in the common decapsulation path covers End.DX4, End.DT4, and
End.DT46's IPv4 arm.
Use IP6CB(skb)->iif rather than skb->skb iif. These actions run after
l3mdev processing, which can replace skb iif with the L3 master;
IP6CB iif still records the receiving interface set at IPv6 ingress.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux