PT-2026-98552 · Linux · Linux

CVE-2026-97612

·

Published

2026-09-25

·

Updated

2026-09-25

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the Linux kernel, the following vulnerability has been resolved:
net: mpls: clear inner protocol when the last label is popped
skb mpls push() records the pre-encapsulation network header once, gated on !skb->inner protocol. skb mpls pop() never clears that record, so it outlives the encapsulation it describes.
Open vSwitch can then re-push MPLS onto a packet whose inner network header still points at the older, deeper offset: push a label, pop every label, recirculate (ovs flow key update() re-derives key->eth.type and resets network header, but leaves inner *), then push again. ovs fragment() trusts the record:
skb->network header = skb->inner network header;
so skb network offset() goes negative. The bound check is signed:
if (skb network offset(skb) > MAX L2 LEN)
a negative offset passes it, and prepare frag() widens the value:
unsigned int hlen = skb network offset(skb);
memcpy(&data->l2 data, skb->data, hlen);
which is a ~4GiB memcpy out of a 30-byte per-CPU buffer.
Reproduced on v7.3-rc1. RDX is the truncated length, (unsigned int)(-8):
BUG: unable to handle page fault for address: ffffe8ffffc16000 #PF: supervisor write access in kernel mode Oops: 0002 [#1] SMP KASAN NOPTI RIP: 0010:memcpy+0x8/0x20 RDX: 00000000fffffff8 RSI: ffff888105d732db RDI: ffffe8ffffc16000 prepare frag+0x3df/0x4e0 ovs fragment+0x589/0x7e0 do output+0x4ce/0x5e0 do execute actions+0x55d2/0x7b30 ovs execute actions+0xea/0x450
Same root-cause shape as commit 975b5b067f52 ("ipv6: sr: restore network header before routing and forwarding"): a stale network header offset reaching a consumer that widens it. Here it originates in the MPLS push/pop path.
Clear inner protocol once the packet is no longer MPLS, so a later push re-records the current header. net/sched/act mpls.c is the only other skb mpls pop() caller and gets the same fix; sch frag.c saves and restores inner protocol around fragmentation in the same way OVS does.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-97612

Affected Products

Linux