« Volver al listado

CVE-2026-90083

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

net/sched: act_ife: Only operate on Ethernet frames

act_ife encapsulates/decapsulates the original Ethernet header and uses skb->dev->hard_header_len as the length of that header. That is only correct for Ethernet devices: on a device where hard_header_len does not match the L2 header that was actually pulled (PPP reports PPP_HDRLEN while nothing is stripped on ingress), the ingress skb_push()/skb_pull() use the wrong length and can hit skb_under_panic when headroom is tight.

IFE is Ethernet-only by design - it builds an outer ethhdr, rewrites h_source/h_dest/h_proto, and calls eth_type_trans() on decode - so instead of trying to make the offsets work for arbitrary link types, simply drop packets that do not carry an Ethernet header.

Leer descripción completaMostrar menos

Checking skb->dev->type alone is not enough. We have to cater for a corner case where mirred can redirect an skb from a non-Ethernet device to an Ethernet one, and skb->dev then says nothing about the framing the skb actually has: an skb redirected from ppp0 reaches the target's ingress hook with mac_len 0 and no Ethernet header at all. So at ingress also require mac_len to be ETH_HLEN. On egress mac_len is not maintained, so the device type is all we have; a bogus redirect there yields a malformed frame rather than an out-of-bounds push, and it would be malformed with or without IFE.

That corner case is not theoretical - redirecting from ppp0 into a veth that has an ife encode action on its ingress hook panics without this patch:

With Ethernet framing guaranteed, use ETH_HLEN instead of hard_header_len.

Detalles técnicos trazas, registros y código del informe original
  skbuff: skb_under_panic: len:98 put:14 head:ffff88800e410000
          data:ffff88800e40fff5 tail:0x57 end:0x640 dev:veth3
  kernel BUG at net/core/skbuff.c:214!
  Call Trace:
   skb_push (net/core/skbuff.c:224 net/core/skbuff.c:2657)
   tcf_ife_act (net/sched/act_ife.c:829 net/sched/act_ife.c:874)
   tc_run (net/core/dev.c:4463)
   netif_receive_skb (net/core/dev.c:6463 net/core/dev.c:6522)
   tcf_mirred_to_dev (net/sched/act_mirred.c:248 net/sched/act_mirred.c:328)
   tcf_mirred_act (net/sched/act_mirred.c:489)
   tc_run (net/core/dev.c:4463)
   process_backlog (net/core/dev.c:6728)

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-90083",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "295a6e06d21e1f469c9f38b00125a13b60ad4e7c",
              "lessThan": "d218ea7df6eba076171f2d4897a429a31f2139f0",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "295a6e06d21e1f469c9f38b00125a13b60ad4e7c",
              "lessThan": "138b0054021fd7d57bc3eb68b3f4e2bcec037849",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "295a6e06d21e1f469c9f38b00125a13b60ad4e7c",
              "lessThan": "5b483f7791b079bb97d411f1066652ff659207ff",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "net/ife/ife.c",
            "net/sched/act_ife.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4.11"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "4.11",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.18.52",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "net/ife/ife.c",
            "net/sched/act_ife.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-17T17:16:57.707",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/138b0054021fd7d57bc3eb68b3f4e2bcec037849",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/5b483f7791b079bb97d411f1066652ff659207ff",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/d218ea7df6eba076171f2d4897a429a31f2139f0",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: act_ife: Only operate on Ethernet frames\n\nact_ife encapsulates/decapsulates the original Ethernet header and uses\nskb->dev->hard_header_len as the length of that header. That is only\ncorrect for Ethernet devices: on a device where hard_header_len does not\nmatch the L2 header that was actually pulled (PPP reports PPP_HDRLEN\nwhile nothing is stripped on ingress), the ingress skb_push()/skb_pull()\nuse the wrong length and can hit skb_under_panic when headroom is tight.\n\nIFE is Ethernet-only by design - it builds an outer ethhdr, rewrites\nh_source/h_dest/h_proto, and calls eth_type_trans() on decode - so\ninstead of trying to make the offsets work for arbitrary link types,\nsimply drop packets that do not carry an Ethernet header.\n\nChecking skb->dev->type alone is not enough. We have to cater for a\ncorner case where mirred can redirect an skb from a non-Ethernet device\nto an Ethernet one, and skb->dev then says nothing about the framing the\nskb actually has: an skb redirected from ppp0 reaches the target's ingress\nhook with mac_len 0 and no Ethernet header at all. So at ingress also\nrequire mac_len to be ETH_HLEN. On egress mac_len is not maintained, so\nthe device type is all we have; a bogus redirect there yields a malformed\nframe rather than an out-of-bounds push, and it would be malformed with or\nwithout IFE.\n\nThat corner case is not theoretical - redirecting from ppp0 into a veth\nthat has an ife encode action on its ingress hook panics without this\npatch:\n\n  skbuff: skb_under_panic: len:98 put:14 head:ffff88800e410000\n          data:ffff88800e40fff5 tail:0x57 end:0x640 dev:veth3\n  kernel BUG at net/core/skbuff.c:214!\n  Call Trace:\n   skb_push (net/core/skbuff.c:224 net/core/skbuff.c:2657)\n   tcf_ife_act (net/sched/act_ife.c:829 net/sched/act_ife.c:874)\n   tc_run (net/core/dev.c:4463)\n   netif_receive_skb (net/core/dev.c:6463 net/core/dev.c:6522)\n   tcf_mirred_to_dev (net/sched/act_mirred.c:248 net/sched/act_mirred.c:328)\n   tcf_mirred_act (net/sched/act_mirred.c:489)\n   tc_run (net/core/dev.c:4463)\n   process_backlog (net/core/dev.c:6728)\n\nWith Ethernet framing guaranteed, use ETH_HLEN instead of\nhard_header_len."
    }
  ],
  "lastModified": "2026-09-17T17:16:57.707",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}