« Volver al listado

CVE-2026-80840

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

ipv6: seg6: clear IPv4 control block on IPIP decapsulation

End.DX4 and End.DT4 decapsulate an IPv4 packet through decap_and_validate() and send it directly to IPv4 routing. The inner packet therefore bypasses ip_rcv_core(), which normally clears IPCB before IPv4 interprets skb->cb.

The skb instead retains IP6CB data from the outer packet. IP6CB and IPCB use the same skb->cb storage, so IP6CB(skb)->lastopt overlaps IPCB(skb)->opt.optlen and srr, while IP6CB(skb)->nhoff overlaps rr and ts.

The sender can make the stale optlen byte nonzero with a valid outer extension-header chain.

Leer descripción completaMostrar menos

The reproducers put an eight-byte Destination Options header immediately after the 40-byte IPv6 header and before the Segment Routing Header. ipv6_destopt_rcv() records the sender-controlled Destination Options offset in both lastopt and nhoff, setting them to 40. On the reproduced little-endian x86-64 kernel, IPv4 therefore sees optlen = 40 and rr = 40.

Both tcp_v4_save_options() and __ip_options_echo() skip option copying when optlen is zero. Here optlen is 40, so the TCP SYN path allocates room for 40 bytes of option data and calls __ip_options_echo(). The stale rr value makes that function read inner packet byte 41 as the Record Route option length. The reproducers set that sender-controlled byte to 255, so __ip_options_echo() copies 255 bytes into the 40-byte option-data area.

Separate End.DX4 and End.DT4 reproducers on the unpatched v7.2-rc5 kernel both produced:

The relevant End.DX4 call path is:

The relevant End.DT4 call path is:

tcp_v4_save_options() is inlined into the tcp_v4_route_req() path, so it does not appear as a separate frame.

When decap_and_validate() handles IPPROTO_IPIP, save the ingress interface from IP6CB, clear IPCB, and restore the saved value. Doing this in the common decapsulation path covers End.DX4, End.DT4, and End.DT46's IPv4 arm.

Use IP6CB(skb)->iif rather than skb->skb_iif. These actions run after l3mdev processing, which can replace skb_iif with the L3 master; IP6CB iif still records the receiving interface set at IPv6 ingress.

Detalles técnicos trazas, registros y código del informe original
  BUG: KASAN: slab-out-of-bounds in __ip_options_echo()
  Write of size 255

  __ip_options_echo
  tcp_v4_route_req
  tcp_conn_request
  tcp_v4_conn_request
  tcp_rcv_state_process
  tcp_v4_do_rcv
  tcp_v4_rcv
  ip_protocol_deliver_rcu
  ip_local_deliver_finish
  ip_local_deliver
  input_action_end_dx4_finish
  input_action_end_dx4

  __ip_options_echo
  tcp_v4_route_req
  tcp_conn_request
  tcp_v4_conn_request
  tcp_rcv_state_process
  tcp_v4_do_rcv
  tcp_v4_rcv
  ip_protocol_deliver_rcu
  ip_local_deliver_finish
  ip_local_deliver
  input_action_end_dt4

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-80840",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "891ef8dd2a8d14e4e73a81dcdb135b574c57f556",
              "lessThan": "10fd1a8f58ac619a9e251f2858e2e2c8fd6cd667",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "891ef8dd2a8d14e4e73a81dcdb135b574c57f556",
              "lessThan": "eb0f422487228e140f3d609b032ac61aedcab8fa",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "891ef8dd2a8d14e4e73a81dcdb135b574c57f556",
              "lessThan": "9039e4f3e1c0ffe2b575b655b3f58fdd10f7e40c",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "891ef8dd2a8d14e4e73a81dcdb135b574c57f556",
              "lessThan": "f52f1e75716d2ee49e013edf204ac92337c72fd8",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "891ef8dd2a8d14e4e73a81dcdb135b574c57f556",
              "lessThan": "0e3f01fe2e704e76af4385b8a1742641885a191c",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "891ef8dd2a8d14e4e73a81dcdb135b574c57f556",
              "lessThan": "3e4476e58343fb8f2fffced9e22d935376b17aaf",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "891ef8dd2a8d14e4e73a81dcdb135b574c57f556",
              "lessThan": "bf1c1151560d11036a144d917fa4c131831342d7",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "891ef8dd2a8d14e4e73a81dcdb135b574c57f556",
              "lessThan": "f4be3b391265e24c7720fc867c50062b436acf33",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "891ef8dd2a8d14e4e73a81dcdb135b574c57f556",
              "lessThan": "44930446dde45a7a90fe1446fa38eb0e2c561646",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "net/ipv6/seg6_local.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4.14"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "4.14",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.269",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.220",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.187",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.156",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.108",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.49",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.13",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.3",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "net/ipv6/seg6_local.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-04T16:18:12.440",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/0e3f01fe2e704e76af4385b8a1742641885a191c",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/10fd1a8f58ac619a9e251f2858e2e2c8fd6cd667",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/3e4476e58343fb8f2fffced9e22d935376b17aaf",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/44930446dde45a7a90fe1446fa38eb0e2c561646",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/9039e4f3e1c0ffe2b575b655b3f58fdd10f7e40c",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/bf1c1151560d11036a144d917fa4c131831342d7",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/eb0f422487228e140f3d609b032ac61aedcab8fa",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/f4be3b391265e24c7720fc867c50062b436acf33",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/f52f1e75716d2ee49e013edf204ac92337c72fd8",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: seg6: clear IPv4 control block on IPIP decapsulation\n\nEnd.DX4 and End.DT4 decapsulate an IPv4 packet through\ndecap_and_validate() and send it directly to IPv4 routing. The inner\npacket therefore bypasses ip_rcv_core(), which normally clears IPCB\nbefore IPv4 interprets skb->cb.\n\nThe skb instead retains IP6CB data from the outer packet. IP6CB and\nIPCB use the same skb->cb storage, so IP6CB(skb)->lastopt overlaps\nIPCB(skb)->opt.optlen and srr, while IP6CB(skb)->nhoff overlaps rr and\nts.\n\nThe sender can make the stale optlen byte nonzero with a valid outer\nextension-header chain. The reproducers put an eight-byte Destination\nOptions header immediately after the 40-byte IPv6 header and before the\nSegment Routing Header. ipv6_destopt_rcv() records the sender-controlled\nDestination Options offset in both lastopt and nhoff, setting them to\n40. On the reproduced little-endian x86-64 kernel, IPv4 therefore sees\noptlen = 40 and rr = 40.\n\nBoth tcp_v4_save_options() and __ip_options_echo() skip option copying\nwhen optlen is zero. Here optlen is 40, so the TCP SYN path allocates\nroom for 40 bytes of option data and calls __ip_options_echo(). The\nstale rr value makes that function read inner packet byte 41 as the\nRecord Route option length. The reproducers set that sender-controlled\nbyte to 255, so __ip_options_echo() copies 255 bytes into the 40-byte\noption-data area.\n\nSeparate End.DX4 and End.DT4 reproducers on the unpatched v7.2-rc5\nkernel both produced:\n\n  BUG: KASAN: slab-out-of-bounds in __ip_options_echo()\n  Write of size 255\n\nThe relevant End.DX4 call path is:\n\n  __ip_options_echo\n  tcp_v4_route_req\n  tcp_conn_request\n  tcp_v4_conn_request\n  tcp_rcv_state_process\n  tcp_v4_do_rcv\n  tcp_v4_rcv\n  ip_protocol_deliver_rcu\n  ip_local_deliver_finish\n  ip_local_deliver\n  input_action_end_dx4_finish\n  input_action_end_dx4\n\nThe relevant End.DT4 call path is:\n\n  __ip_options_echo\n  tcp_v4_route_req\n  tcp_conn_request\n  tcp_v4_conn_request\n  tcp_rcv_state_process\n  tcp_v4_do_rcv\n  tcp_v4_rcv\n  ip_protocol_deliver_rcu\n  ip_local_deliver_finish\n  ip_local_deliver\n  input_action_end_dt4\n\ntcp_v4_save_options() is inlined into the tcp_v4_route_req() path, so\nit does not appear as a separate frame.\n\nWhen decap_and_validate() handles IPPROTO_IPIP, save the ingress\ninterface from IP6CB, clear IPCB, and restore the saved value. Doing\nthis in the common decapsulation path covers End.DX4, End.DT4, and\nEnd.DT46's IPv4 arm.\n\nUse IP6CB(skb)->iif rather than skb->skb_iif. These actions run after\nl3mdev processing, which can replace skb_iif with the L3 master;\nIP6CB iif still records the receiving interface set at IPv6 ingress."
    }
  ],
  "lastModified": "2026-09-04T16:18:12.440",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}