« Volver al listado

CVE-2026-97965

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

vxlan: initialize _md in vxlan_xmit_one()

If a VXLAN device is configured with both VXLAN_F_COLLECT_METADATA and VXLAN_F_GBP, and a packet is transmitted through it using an external ip_tunnel_info that lacks the IP_TUNNEL_VXLAN_OPT_BIT flag, md is left pointing to the uninitialized _md stack variable:

Because IP_TUNNEL_VXLAN_OPT_BIT is not set, md is not updated and remains pointing to _md. Later, vxlan_build_skb() is called with md, which eventually calls vxlan_build_gbp_hdr():

Inside vxlan_build_gbp_hdr(), md->gbp is read:

If the stack contains garbage, this causes: 1) VXLAN_HF_GBP flag to be spuriously set in the VXLAN header. 2) gbp->dont_learn and gbp->policy_applied to be set from stack bits.

Leer descripción completaMostrar menos

3) gbp->policy_id to receive 16 bits of uninitialized kernel stack data, leaking it onto the wire.

Fix this by zero-initializing _md. If IP_TUNNEL_VXLAN_OPT_BIT is not present, md->gbp remains 0, and vxlan_build_gbp_hdr() returns early without modifying the VXLAN header.

Detalles técnicos trazas, registros y código del informe original
                if (test_bit(IP_TUNNEL_VXLAN_OPT_BIT, info->key.tun_flags)) {
                        if (info->options_len < sizeof(*md))
                                goto drop;
                        md = ip_tunnel_info_opts(info);
                }

        if (vxflags & VXLAN_F_GBP)
                vxlan_build_gbp_hdr(vxh, md);

        if (!md->gbp)
                return;
        gbp = (struct vxlanhdr_gbp *)vxh;
        ...
        if (md->gbp & VXLAN_GBP_DONT_LEARN)
                gbp->dont_learn = 1;

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-97965",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "ee122c79d4227f6ec642157834b6a90fcffa4382",
              "lessThan": "0d13b5a413bffc8718b3821b78537ccc6596c233",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "ee122c79d4227f6ec642157834b6a90fcffa4382",
              "lessThan": "bfb74c48ac2d31476d5e09cf9658844508d2608a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "ee122c79d4227f6ec642157834b6a90fcffa4382",
              "lessThan": "081f22177d9d12b1e381b787f203cd5f47508187",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "ee122c79d4227f6ec642157834b6a90fcffa4382",
              "lessThan": "be83178bfc44588f6e3adb827ed874c683193466",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/net/vxlan/vxlan_core.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4.3"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "4.3",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.12.111",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.53",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.7",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc3",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/net/vxlan/vxlan_core.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-25T11:17:24.293",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/081f22177d9d12b1e381b787f203cd5f47508187",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/0d13b5a413bffc8718b3821b78537ccc6596c233",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/be83178bfc44588f6e3adb827ed874c683193466",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/bfb74c48ac2d31476d5e09cf9658844508d2608a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nvxlan: initialize _md in vxlan_xmit_one()\n\nIf a VXLAN device is configured with both VXLAN_F_COLLECT_METADATA and\nVXLAN_F_GBP, and a packet is transmitted through it using an external\nip_tunnel_info that lacks the IP_TUNNEL_VXLAN_OPT_BIT flag, md is left\npointing to the uninitialized _md stack variable:\n\n                if (test_bit(IP_TUNNEL_VXLAN_OPT_BIT, info->key.tun_flags)) {\n                        if (info->options_len < sizeof(*md))\n                                goto drop;\n                        md = ip_tunnel_info_opts(info);\n                }\n\nBecause IP_TUNNEL_VXLAN_OPT_BIT is not set, md is not updated and remains\npointing to _md. Later, vxlan_build_skb() is called with md, which\neventually calls vxlan_build_gbp_hdr():\n\n        if (vxflags & VXLAN_F_GBP)\n                vxlan_build_gbp_hdr(vxh, md);\n\nInside vxlan_build_gbp_hdr(), md->gbp is read:\n\n        if (!md->gbp)\n                return;\n        gbp = (struct vxlanhdr_gbp *)vxh;\n        ...\n        if (md->gbp & VXLAN_GBP_DONT_LEARN)\n                gbp->dont_learn = 1;\n\nIf the stack contains garbage, this causes:\n1) VXLAN_HF_GBP flag to be spuriously set in the VXLAN header.\n2) gbp->dont_learn and gbp->policy_applied to be set from stack bits.\n3) gbp->policy_id to receive 16 bits of uninitialized kernel stack data,\n   leaking it onto the wire.\n\nFix this by zero-initializing _md. If IP_TUNNEL_VXLAN_OPT_BIT is not\npresent, md->gbp remains 0, and vxlan_build_gbp_hdr() returns early\nwithout modifying the VXLAN header."
    }
  ],
  "lastModified": "2026-09-25T11:17:24.293",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}