PT-2026-98552 · Linux · Linux
CVE-2026-97612
·
Published
2026-09-25
·
Updated
2026-09-25
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
In the Linux kernel, the following vulnerability has been resolved:
net: mpls: clear inner protocol when the last label is popped
skb mpls push() records the pre-encapsulation network header once, gated
on !skb->inner protocol. skb mpls pop() never clears that record, so it
outlives the encapsulation it describes.
Open vSwitch can then re-push MPLS onto a packet whose
inner network header still points at the older, deeper offset: push a
label, pop every label, recirculate (ovs flow key update() re-derives
key->eth.type and resets network header, but leaves inner *), then push
again. ovs fragment() trusts the record:
skb->network header = skb->inner network header;so skb network offset() goes negative. The bound check is signed:
if (skb network offset(skb) > MAX L2 LEN)a negative offset passes it, and prepare frag() widens the value:
unsigned int hlen = skb network offset(skb);
memcpy(&data->l2 data, skb->data, hlen);which is a ~4GiB memcpy out of a 30-byte per-CPU buffer.
Reproduced on v7.3-rc1. RDX is the truncated length, (unsigned int)(-8):
BUG: unable to handle page fault for address: ffffe8ffffc16000
#PF: supervisor write access in kernel mode
Oops: 0002 [#1] SMP KASAN NOPTI
RIP: 0010:memcpy+0x8/0x20
RDX: 00000000fffffff8 RSI: ffff888105d732db RDI: ffffe8ffffc16000
prepare frag+0x3df/0x4e0
ovs fragment+0x589/0x7e0
do output+0x4ce/0x5e0
do execute actions+0x55d2/0x7b30
ovs execute actions+0xea/0x450
Same root-cause shape as commit 975b5b067f52 ("ipv6: sr: restore network
header before routing and forwarding"): a stale network header offset
reaching a consumer that widens it. Here it originates in the MPLS
push/pop path.
Clear inner protocol once the packet is no longer MPLS, so a later push
re-records the current header. net/sched/act mpls.c is the only other
skb mpls pop() caller and gets the same fix; sch frag.c saves and
restores inner protocol around fragmentation in the same way OVS does.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux