« Volver al listado

CVE-2026-98317

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

neighbour: Enforce min/max to NDTPA_INTERVAL_PROBE_TIME_MS.

NDTPA_INTERVAL_PROBE_TIME_MS sets .type and .min but misses .validation_type, so no validation is applied:

Moreover, nla_get_msecs() uses msecs_to_jiffies(), and u64 is silently cast to u32, so a larger value can bypass the min check:

msecs_to_jiffies() returns MAX_JIFFY_OFFSET if the value is larger than INT_MAX. Also, INT_MAX ms overflows int NEIGH_VAR() when HZ > 1000 (Alpha, MIPS), and passing a negative integer to queue_delayed_work(unsigned long delay) causes sign extension, which wraps around the expiry time to the past, resulting in it being handled as 0 delay in the timer wheel.

Leer descripción completaMostrar menos

Let's use NLA_POLICY_FULL_RANGE() and limit the max to 1 day.

The same max check is applied to sysctl as well.

Note that this controls the probe interval for NTF_MANAGED entries, so the max of 1 day is unlikely to break any deployments.

Detalles técnicos trazas, registros y código del informe original
  # ynl --family rt-neigh --do setneightbl \
  --json '{"name": "arp_cache", "parms": {"interval-probe-time-ms": 0}}'

  # ynl --family rt-neigh --dump getneightbl --output-json | \
  jq '.[] | select(.name == "arp_cache" and has("config"))
          | .parms["interval-probe-time-ms"]'
  0

  e.g. 4294967296 == 0x100000000

  # ynl --family rt-neigh --do setneightbl \
  --json '{"name": "arp_cache", "parms": {"interval-probe-time-ms": 4294967296}}'

  # ynl --family rt-neigh --dump getneightbl --output-json | \
  jq '.[] | select(.name == "arp_cache" and has("config"))
          | .parms["interval-probe-time-ms"]'
  0

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-98317",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "211da42eaa45db7b0edfde187dd88a85fbd466b5",
              "lessThan": "982c7f66c04134b77126edbfd8a63ecd6928cfd9",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "211da42eaa45db7b0edfde187dd88a85fbd466b5",
              "lessThan": "8550b50e49b01b572e653e572f24ddd73949aa74",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "211da42eaa45db7b0edfde187dd88a85fbd466b5",
              "lessThan": "6d79b223ec44ada58ad37db42f539b60985a7722",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "Documentation/netlink/specs/rt-neigh.yaml",
            "Documentation/networking/ip-sysctl.rst",
            "net/core/neighbour.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.0"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.0",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.18.54",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.8",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc4",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "Documentation/netlink/specs/rt-neigh.yaml",
            "Documentation/networking/ip-sysctl.rst",
            "net/core/neighbour.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-10-06T09:18:23.530",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/6d79b223ec44ada58ad37db42f539b60985a7722",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/8550b50e49b01b572e653e572f24ddd73949aa74",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/982c7f66c04134b77126edbfd8a63ecd6928cfd9",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nneighbour: Enforce min/max to NDTPA_INTERVAL_PROBE_TIME_MS.\n\nNDTPA_INTERVAL_PROBE_TIME_MS sets .type and .min but misses\n.validation_type, so no validation is applied:\n\n  # ynl --family rt-neigh --do setneightbl \\\n  --json '{\"name\": \"arp_cache\", \"parms\": {\"interval-probe-time-ms\": 0}}'\n\n  # ynl --family rt-neigh --dump getneightbl --output-json | \\\n  jq '.[] | select(.name == \"arp_cache\" and has(\"config\"))\n          | .parms[\"interval-probe-time-ms\"]'\n  0\n\nMoreover, nla_get_msecs() uses msecs_to_jiffies(), and u64 is\nsilently cast to u32, so a larger value can bypass the min check:\n\n  e.g. 4294967296 == 0x100000000\n\n  # ynl --family rt-neigh --do setneightbl \\\n  --json '{\"name\": \"arp_cache\", \"parms\": {\"interval-probe-time-ms\": 4294967296}}'\n\n  # ynl --family rt-neigh --dump getneightbl --output-json | \\\n  jq '.[] | select(.name == \"arp_cache\" and has(\"config\"))\n          | .parms[\"interval-probe-time-ms\"]'\n  0\n\nmsecs_to_jiffies() returns MAX_JIFFY_OFFSET if the value is\nlarger than INT_MAX.  Also, INT_MAX ms overflows int NEIGH_VAR()\nwhen HZ > 1000 (Alpha, MIPS), and passing a negative integer to\nqueue_delayed_work(unsigned long delay) causes sign extension,\nwhich wraps around the expiry time to the past, resulting in it\nbeing handled as 0 delay in the timer wheel.\n\nLet's use NLA_POLICY_FULL_RANGE() and limit the max to 1 day.\n\nThe same max check is applied to sysctl as well.\n\nNote that this controls the probe interval for NTF_MANAGED\nentries, so the max of 1 day is unlikely to break any\ndeployments."
    }
  ],
  "lastModified": "2026-10-06T09:18:23.530",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}