« Volver al listado

CVE-2026-98158

Estado: En análisisSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

ppp_async: drop the errored frame instead of resetting its headroom

ppp_receive_nonmp_frame() prepends a two-byte direction tag before running the pass/active BPF filters:

Nothing on the receive path guarantees those two bytes of headroom. The frame-error path in ppp_async's process_input_packet() resets a reused skb's headroom to zero while claiming to restore it to a freshly allocated state - but a fresh skb from dev_alloc_skb() carries NET_SKB_PAD:

ap->rpkt still points at that skb, so the next frame is reassembled into it with no headroom at all.

Leer descripción completaMostrar menos

A peer that sends a bad-FCS frame followed by one beginning ff 03 then leaves a single byte of headroom by the time the filter tag is pushed, which lands one byte below skb->head:

Zeroing the headroom violates the NET_SKB_PAD guarantee that dev_alloc_skb() gives the rest of the receive path. Besides the filter panic above, when CCP compression is enabled ppp_decompress_frame() hands skb->data - 2 to ->decompress()/->incomp(), which then reads out of bounds before skb->head for the same reason.

Rather than restore the headroom, drop the errored frame - as ppp_synctty already does on its error path - and clear ap->rpkt so the next frame is reassembled into a fresh skb with proper headroom. This is simpler and fixes both the filter under-panic and the CCP out-of-bounds read.

The original V1 of this patch made room in ppp_receive_nonmp_frame() with skb_cow_head(); Eric pointed out that fixing the root cause in the transport is the right approach.

Found by fuzzing the PPP receive path with a mutating peer on a pty; it is an interesting (remote) DoS: root configures PPP, the peer supplies two crashing frames. The reproducer (repro-ppp-skb.c, unchanged from v1) panics in about a second, and returns cleanly with this applied.

Detalles técnicos trazas, registros y código del informe original
	*(__be16 *)skb_push(skb, 2) = htons(PPP_FILTER_INBOUND_TAG);

	err:
		if (skb) {
			/* make skb appear as freshly allocated */
			skb_trim(skb, 0);
			skb_reserve(skb, - skb_headroom(skb));
		}

  skbuff: skb_under_panic: len:49 put:2 head:ffff888003c10000
          data:ffff888003c0ffff tail:0x30 end:0x640 dev:<NULL>
  kernel BUG at net/core/skbuff.c:214!
  RIP: 0010:skb_panic+0x13e/0x230
  Call Trace:
   skb_push+0xbd/0x100
   ppp_receive_nonmp_frame+0x48a/0x1d10
   ppp_input+0x4e9/0x2f80
   ppp_async_process+0x2a/0xe0
   tasklet_action_common+0x20f/0x8a0
   handle_softirqs+0x18e/0x590
  Kernel panic - not syncing: Fatal exception in interrupt

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-98158",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6722e78c90054101e6797d5944cdc81af9897a0a",
              "lessThan": "25f354c55b8435d1f51b8a0a05a3cfe429358523",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "6722e78c90054101e6797d5944cdc81af9897a0a",
              "lessThan": "a86a17745c3e1c6fadd4d6e90c03552dfe531c8c",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "6722e78c90054101e6797d5944cdc81af9897a0a",
              "lessThan": "ff035780adb0f49dc2c7ada26b4697849a68bec8",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "6722e78c90054101e6797d5944cdc81af9897a0a",
              "lessThan": "c4bb894362d224b699e2f95c6c26707d9654e4a3",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "6722e78c90054101e6797d5944cdc81af9897a0a",
              "lessThan": "d0fc3dabfe67caf084e7119ceb2ee23f5ad2f2da",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "6722e78c90054101e6797d5944cdc81af9897a0a",
              "lessThan": "0c53eb14975f029abd6b26896a460f0d2aaefe6b",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "6722e78c90054101e6797d5944cdc81af9897a0a",
              "lessThan": "717137221c7d90e7c98bda9a370c9da6cbf015e5",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "6722e78c90054101e6797d5944cdc81af9897a0a",
              "lessThan": "8dc5d98a16fa23c00999aecf10018c9f69fa5bf4",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/net/ppp/ppp_async.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "2.6.15"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "2.6.15",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.271",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.222",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.189",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.158",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.111",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.53",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.7",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc3",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/net/ppp/ppp_async.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-25T11:17:47.510",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/0c53eb14975f029abd6b26896a460f0d2aaefe6b",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/25f354c55b8435d1f51b8a0a05a3cfe429358523",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/717137221c7d90e7c98bda9a370c9da6cbf015e5",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/8dc5d98a16fa23c00999aecf10018c9f69fa5bf4",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/a86a17745c3e1c6fadd4d6e90c03552dfe531c8c",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/c4bb894362d224b699e2f95c6c26707d9654e4a3",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/d0fc3dabfe67caf084e7119ceb2ee23f5ad2f2da",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/ff035780adb0f49dc2c7ada26b4697849a68bec8",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Undergoing Analysis",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nppp_async: drop the errored frame instead of resetting its headroom\n\nppp_receive_nonmp_frame() prepends a two-byte direction tag before running\nthe pass/active BPF filters:\n\n\t*(__be16 *)skb_push(skb, 2) = htons(PPP_FILTER_INBOUND_TAG);\n\nNothing on the receive path guarantees those two bytes of headroom. The\nframe-error path in ppp_async's process_input_packet() resets a reused skb's\nheadroom to zero while claiming to restore it to a freshly allocated state -\nbut a fresh skb from dev_alloc_skb() carries NET_SKB_PAD:\n\n\terr:\n\t\tif (skb) {\n\t\t\t/* make skb appear as freshly allocated */\n\t\t\tskb_trim(skb, 0);\n\t\t\tskb_reserve(skb, - skb_headroom(skb));\n\t\t}\n\nap->rpkt still points at that skb, so the next frame is reassembled into it\nwith no headroom at all. A peer that sends a bad-FCS frame followed by one\nbeginning ff 03 then leaves a single byte of headroom by the time the filter\ntag is pushed, which lands one byte below skb->head:\n\n  skbuff: skb_under_panic: len:49 put:2 head:ffff888003c10000\n          data:ffff888003c0ffff tail:0x30 end:0x640 dev:<NULL>\n  kernel BUG at net/core/skbuff.c:214!\n  RIP: 0010:skb_panic+0x13e/0x230\n  Call Trace:\n   skb_push+0xbd/0x100\n   ppp_receive_nonmp_frame+0x48a/0x1d10\n   ppp_input+0x4e9/0x2f80\n   ppp_async_process+0x2a/0xe0\n   tasklet_action_common+0x20f/0x8a0\n   handle_softirqs+0x18e/0x590\n  Kernel panic - not syncing: Fatal exception in interrupt\n\nZeroing the headroom violates the NET_SKB_PAD guarantee that dev_alloc_skb()\ngives the rest of the receive path. Besides the filter panic above, when CCP\ncompression is enabled ppp_decompress_frame() hands skb->data - 2 to\n->decompress()/->incomp(), which then reads out of bounds before skb->head\nfor the same reason.\n\nRather than restore the headroom, drop the errored frame - as ppp_synctty\nalready does on its error path - and clear ap->rpkt so the next frame is\nreassembled into a fresh skb with proper headroom. This is simpler and fixes\nboth the filter under-panic and the CCP out-of-bounds read.\n\nThe original V1 of this patch made room in ppp_receive_nonmp_frame() with\nskb_cow_head(); Eric pointed out that fixing the root cause in the transport\nis the right approach.\n\nFound by fuzzing the PPP receive path with a mutating peer on a pty; it is an\ninteresting (remote) DoS: root configures PPP, the peer supplies two crashing\nframes. The reproducer (repro-ppp-skb.c, unchanged from v1) panics in about a\nsecond, and returns cleanly with this applied."
    }
  ],
  "lastModified": "2026-10-03T11:18:37.947",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}