CVE-2026-97964
In the Linux kernel, the following vulnerability has been resolved:
ppp_synctty: ensure a writeable skb header
ppp_sync_txmunge() checks headroom before prepending the address and control bytes, but does not ensure that the skb header is writable. A received skb can reach this function through PPP channel bridging without passing through ppp_start_xmit(), which calls skb_cow_head().
For example, a PPPoE frame may share its buffer with a clone queued to an AF_PACKET socket. If it is bridged to a synchronous tty channel, the address/control bytes can overwrite data still visible to that socket.
Use skb_cow_head() to ensure both sufficient headroom and a writable header.
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.17%
- Percentil entre todas las CVEs puntuadas: 6
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/0996c3e6bcc6ae08cb371ed43648c9f7f748ae6e
- https://git.kernel.org/stable/c/15d0a6c9a42df2d745c37510dba828f6dbe60d9f
- https://git.kernel.org/stable/c/25e03eeead2c49748c7582dfb64c205f93a42d00
- https://git.kernel.org/stable/c/3af7797fbabc84992e0ca5ad2bc0ca8537d053ef
- https://git.kernel.org/stable/c/7953946f68262a8bb137aa101249adef6e029652
- https://git.kernel.org/stable/c/8aaeb56aff2a557a88f83ae866da2c91ad247e59
- https://git.kernel.org/stable/c/a256f9925288ef47de8febed5c38d5cc21340211
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-97964",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "4cf476ced45d7f12df30a68e833b263e7a2202d1",
"lessThan": "25e03eeead2c49748c7582dfb64c205f93a42d00",
"versionType": "git"
},
{
"status": "affected",
"version": "4cf476ced45d7f12df30a68e833b263e7a2202d1",
"lessThan": "a256f9925288ef47de8febed5c38d5cc21340211",
"versionType": "git"
},
{
"status": "affected",
"version": "4cf476ced45d7f12df30a68e833b263e7a2202d1",
"lessThan": "7953946f68262a8bb137aa101249adef6e029652",
"versionType": "git"
},
{
"status": "affected",
"version": "4cf476ced45d7f12df30a68e833b263e7a2202d1",
"lessThan": "3af7797fbabc84992e0ca5ad2bc0ca8537d053ef",
"versionType": "git"
},
{
"status": "affected",
"version": "4cf476ced45d7f12df30a68e833b263e7a2202d1",
"lessThan": "0996c3e6bcc6ae08cb371ed43648c9f7f748ae6e",
"versionType": "git"
},
{
"status": "affected",
"version": "4cf476ced45d7f12df30a68e833b263e7a2202d1",
"lessThan": "15d0a6c9a42df2d745c37510dba828f6dbe60d9f",
"versionType": "git"
},
{
"status": "affected",
"version": "4cf476ced45d7f12df30a68e833b263e7a2202d1",
"lessThan": "8aaeb56aff2a557a88f83ae866da2c91ad247e59",
"versionType": "git"
}
],
"programFiles": [
"drivers/net/ppp/ppp_synctty.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "5.11"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "5.11",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.15.222",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.189",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.158",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.111",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.53",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2.7",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc3",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/net/ppp/ppp_synctty.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-25T11:17:24.187",
"references": [
{
"url": "https://git.kernel.org/stable/c/0996c3e6bcc6ae08cb371ed43648c9f7f748ae6e",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/15d0a6c9a42df2d745c37510dba828f6dbe60d9f",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/25e03eeead2c49748c7582dfb64c205f93a42d00",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/3af7797fbabc84992e0ca5ad2bc0ca8537d053ef",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/7953946f68262a8bb137aa101249adef6e029652",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/8aaeb56aff2a557a88f83ae866da2c91ad247e59",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/a256f9925288ef47de8febed5c38d5cc21340211",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nppp_synctty: ensure a writeable skb header\n\nppp_sync_txmunge() checks headroom before prepending the address and\ncontrol bytes, but does not ensure that the skb header is writable.\nA received skb can reach this function through PPP channel bridging\nwithout passing through ppp_start_xmit(), which calls skb_cow_head().\n\nFor example, a PPPoE frame may share its buffer with a clone queued to\nan AF_PACKET socket. If it is bridged to a synchronous tty channel, the\naddress/control bytes can overwrite data still visible to that socket.\n\nUse skb_cow_head() to ensure both sufficient headroom and a writable\nheader."
}
],
"lastModified": "2026-10-03T11:18:21.377",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}