« Volver al listado

CVE-2026-72407

Estado: RecibidaCrítica (10)—

In the Linux kernel, the following vulnerability has been resolved:

geneve: validate inner network offset in geneve_gro_complete()

Even with both paths gated on gs->gro_hint, geneve_gro_complete() re-derives the inner dispatch type and length from the packet and the current gs->gro_hint, independently of geneve_gro_receive(). The two can disagree if gs->gro_hint flips under a concurrent geneve_quiesce()/ geneve_unquiesce() (sk_user_data is NULL across a synchronize_net()), or if the re-read option bytes differ from the ones receive parsed.

geneve_gro_receive() already records the inner network header position in NAPI_GRO_CB()->inner_network_offset.

Leer descripción completaMostrar menos

Have geneve_gro_complete() compute the offset it is about to dispatch at, adding ETH_HLEN in the ETH_P_TEB case where eth_gro_complete() steps over the inner MAC header, and bail out if it lands past inner_network_offset.

Use a lower bound rather than exact equality: between gh_len and the inner L3 header, geneve_gro_receive() may also have pulled an inner VLAN tag (vlan_gro_receive() advances the recorded offset past it), which only moves inner_network_offset further out. A valid frame therefore always satisfies inner_nh <= inner_network_offset, while a gh_len inflated by a hint gro_receive() did not honour dispatches past the validated inner header, i.e. the out-of-bounds completion. Only the latter is rejected.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vulnerabilidad remota en Linux kernel sin autenticación (AV:N, PR:N, UI:N) que permite escalada de privilegios mediante manipulación de paquetes GRO en geneve_gro_complete() (acceso y corrupción de memoria, desbordamiento). Impacto crítico en confidencialidad, integridad y disponibilidad (C:H/I:H/A:

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-72407",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 10,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "fd0dd796576e1a560e1441e665810129f0a82be0",
              "lessThan": "e2087447f562692ff0cd08a0554d8d4ad083aa5c",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "fd0dd796576e1a560e1441e665810129f0a82be0",
              "lessThan": "cbb0d30a1ad6fc9439b1dc9b4f5a7a9140d3b11f",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/net/geneve.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "7.0"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "7.0",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "7.1.5",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/net/geneve.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-08-15T06:22:14.300",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/cbb0d30a1ad6fc9439b1dc9b4f5a7a9140d3b11f",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/e2087447f562692ff0cd08a0554d8d4ad083aa5c",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ngeneve: validate inner network offset in geneve_gro_complete()\n\nEven with both paths gated on gs->gro_hint, geneve_gro_complete()\nre-derives the inner dispatch type and length from the packet and the\ncurrent gs->gro_hint, independently of geneve_gro_receive(). The two can\ndisagree if gs->gro_hint flips under a concurrent geneve_quiesce()/\ngeneve_unquiesce() (sk_user_data is NULL across a synchronize_net()), or if\nthe re-read option bytes differ from the ones receive parsed.\n\ngeneve_gro_receive() already records the inner network header position in\nNAPI_GRO_CB()->inner_network_offset. Have geneve_gro_complete() compute the\noffset it is about to dispatch at, adding ETH_HLEN in the ETH_P_TEB case\nwhere eth_gro_complete() steps over the inner MAC header, and bail out if\nit lands past inner_network_offset.\n\nUse a lower bound rather than exact equality: between gh_len and the inner\nL3 header, geneve_gro_receive() may also have pulled an inner VLAN tag\n(vlan_gro_receive() advances the recorded offset past it), which only moves\ninner_network_offset further out. A valid frame therefore always satisfies\ninner_nh <= inner_network_offset, while a gh_len inflated by a hint\ngro_receive() did not honour dispatches past the validated inner header,\ni.e. the out-of-bounds completion. Only the latter is rejected."
    }
  ],
  "lastModified": "2026-08-17T06:19:07.453",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}