« Volver al listado

CVE-2026-72400

Estado: RecibidaAlta (7.8)—

In the Linux kernel, the following vulnerability has been resolved:

seg6: validate SRH length before reading fixed fields

seg6_validate_srh() reads fixed SRH fields such as srh->type and srh->hdrlen before checking that the supplied length covers the fixed struct ipv6_sr_hdr fields.

The BPF SEG6 encap path reaches this with a BPF program-supplied pointer and length: bpf_lwt_push_encap() and the SEG6 local BPF END_B6 and END_B6_ENCAP actions call bpf_push_seg6_encap(), which forwards the length to seg6_validate_srh() with no minimum-size guard. A 2-byte SEG6 encap header can therefore make the validator read srh->type at offset 2 beyond the caller-supplied buffer.

Leer descripción completaMostrar menos

Reject lengths shorter than the fixed SRH at the top of seg6_validate_srh(), before any field is read. This fixes the BPF helper path and keeps the common validator robust.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Acceso local (AV:L) sin interacción (UI:N) con privilegios (PR:L) permite escalada; lectura de memoria más allá del buffer y DoS por out-of-bounds en kernel SEG6.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-72400",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "fe94cc290f535709d3c5ebd1e472dfd0aec7ee79",
              "lessThan": "715eb12e453df752f1b4baaf972c3acff0ab9402",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "fe94cc290f535709d3c5ebd1e472dfd0aec7ee79",
              "lessThan": "7247d05c987c3eec4bb7c2306dbd77ecdf3b7c73",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "fe94cc290f535709d3c5ebd1e472dfd0aec7ee79",
              "lessThan": "071f1a38d7ddbadee29c09b9e3ee0ff3a61e6a0e",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "fe94cc290f535709d3c5ebd1e472dfd0aec7ee79",
              "lessThan": "804bb969f194c93497ba632b98343794c6367fdc",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "fe94cc290f535709d3c5ebd1e472dfd0aec7ee79",
              "lessThan": "0fc7069d39239978130c37ebceaec85c8948d3f1",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "fe94cc290f535709d3c5ebd1e472dfd0aec7ee79",
              "lessThan": "8dba7a94a269b88e500aafc25ad567ef6a423698",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "fe94cc290f535709d3c5ebd1e472dfd0aec7ee79",
              "lessThan": "c9961336aa5ff83092f23e33ee86666a9dbd1b2a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "fe94cc290f535709d3c5ebd1e472dfd0aec7ee79",
              "lessThan": "a75d99f46bf21b45965ce39c5cfb3b8bb5ffb1aa",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "net/ipv6/seg6.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4.18"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "4.18",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.261",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.212",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.178",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.145",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.97",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.40",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.5",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "net/ipv6/seg6.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-08-15T06:22:13.567",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/071f1a38d7ddbadee29c09b9e3ee0ff3a61e6a0e",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/0fc7069d39239978130c37ebceaec85c8948d3f1",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/715eb12e453df752f1b4baaf972c3acff0ab9402",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/7247d05c987c3eec4bb7c2306dbd77ecdf3b7c73",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/804bb969f194c93497ba632b98343794c6367fdc",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/8dba7a94a269b88e500aafc25ad567ef6a423698",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/a75d99f46bf21b45965ce39c5cfb3b8bb5ffb1aa",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/c9961336aa5ff83092f23e33ee86666a9dbd1b2a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nseg6: validate SRH length before reading fixed fields\n\nseg6_validate_srh() reads fixed SRH fields such as srh->type and\nsrh->hdrlen before checking that the supplied length covers the fixed\nstruct ipv6_sr_hdr fields.\n\nThe BPF SEG6 encap path reaches this with a BPF program-supplied pointer\nand length: bpf_lwt_push_encap() and the SEG6 local BPF END_B6 and\nEND_B6_ENCAP actions call bpf_push_seg6_encap(), which forwards the\nlength to seg6_validate_srh() with no minimum-size guard.  A 2-byte SEG6\nencap header can therefore make the validator read srh->type at offset 2\nbeyond the caller-supplied buffer.\n\nReject lengths shorter than the fixed SRH at the top of\nseg6_validate_srh(), before any field is read.  This fixes the BPF helper\npath and keeps the common validator robust."
    }
  ],
  "lastModified": "2026-08-17T06:19:06.633",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}