CVE-2026-74577
In the Linux kernel, the following vulnerability has been resolved:
net: mpls: initialize rtm_tos in mpls_getroute()
mpls_getroute() builds the RTM_NEWROUTE reply to an RTM_GETROUTE request by filling a struct rtmsg allocated from an skb whose data area is not zeroed (alloc_skb(NLMSG_GOODSIZE, ...)). It sets every field of the header except rtm_tos:
struct rtmsg has no padding, so the one uninitialised byte rtm_tos (offset 3) is copied straight to user space on recvmsg(), leaking a byte of uninitialised heap memory. This is in contrast to mpls_dump_route(), which fills the very same header and does set rtm_tos = 0.
Leer descripción completaMostrar menos
Initialize rtm_tos to 0, matching mpls_dump_route().
Reproduced with KMSAN by adding an MPLS route and issuing a non-RTM_F_FIB_MATCH RTM_GETROUTE for its label:
(byte 19 = nlmsghdr(16) + rtmsg offset 3 = rtm_tos)
Detalles técnicos trazas, registros y código del informe original
r = nlmsg_data(nlh); r->rtm_family = AF_MPLS; r->rtm_dst_len = 20; r->rtm_src_len = 0; r->rtm_table = RT_TABLE_MAIN; r->rtm_type = RTN_UNICAST; r->rtm_scope = RT_SCOPE_UNIVERSE; r->rtm_protocol = rt->rt_protocol; r->rtm_flags = 0; BUG: KMSAN: kernel-infoleak in _copy_to_iter+0x36c/0x33f0 _copy_to_iter+0x36c/0x33f0 __skb_datagram_iter+0x196/0x12c0 skb_copy_datagram_iter+0x5b/0x210 netlink_recvmsg+0x37b/0xef0 ... Uninit was created at: __alloc_skb+0x8ca/0x10e0 mpls_getroute+0x1280/0x3a40 rtnetlink_rcv_msg+0x1138/0x15a0 ... Byte 19 of 64 is uninitialized
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.17%
- Percentil entre todas las CVEs puntuadas: 5
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/1fea5ff0eb4aa7e951bb3d380248566c473aa377
- https://git.kernel.org/stable/c/248718fd88b146d8bdc7610ecd1eb4cd16e0b5a1
- https://git.kernel.org/stable/c/295dd295e2137e10e9a5b1891d97e0f08de76f03
- https://git.kernel.org/stable/c/2dc2fffc704a4365cae1aae078ba62223aaeff93
- https://git.kernel.org/stable/c/466b474a8deb0c93b5280c6d261e5eda6482eca7
- https://git.kernel.org/stable/c/95651461cf77cc6590fa08c87667717e5dcfa55d
- https://git.kernel.org/stable/c/a5cdd2407dd890f741f59b8367e4c6c101cce154
- https://git.kernel.org/stable/c/ba56f88aab18d982f2a21f11390f4d8a8897782a
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-74577",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "397fc9e5cefee0c33b86811fbddb0decb7288c52",
"lessThan": "248718fd88b146d8bdc7610ecd1eb4cd16e0b5a1",
"versionType": "git"
},
{
"status": "affected",
"version": "397fc9e5cefee0c33b86811fbddb0decb7288c52",
"lessThan": "466b474a8deb0c93b5280c6d261e5eda6482eca7",
"versionType": "git"
},
{
"status": "affected",
"version": "397fc9e5cefee0c33b86811fbddb0decb7288c52",
"lessThan": "ba56f88aab18d982f2a21f11390f4d8a8897782a",
"versionType": "git"
},
{
"status": "affected",
"version": "397fc9e5cefee0c33b86811fbddb0decb7288c52",
"lessThan": "95651461cf77cc6590fa08c87667717e5dcfa55d",
"versionType": "git"
},
{
"status": "affected",
"version": "397fc9e5cefee0c33b86811fbddb0decb7288c52",
"lessThan": "1fea5ff0eb4aa7e951bb3d380248566c473aa377",
"versionType": "git"
},
{
"status": "affected",
"version": "397fc9e5cefee0c33b86811fbddb0decb7288c52",
"lessThan": "a5cdd2407dd890f741f59b8367e4c6c101cce154",
"versionType": "git"
},
{
"status": "affected",
"version": "397fc9e5cefee0c33b86811fbddb0decb7288c52",
"lessThan": "2dc2fffc704a4365cae1aae078ba62223aaeff93",
"versionType": "git"
},
{
"status": "affected",
"version": "397fc9e5cefee0c33b86811fbddb0decb7288c52",
"lessThan": "295dd295e2137e10e9a5b1891d97e0f08de76f03",
"versionType": "git"
}
],
"programFiles": [
"net/mpls/af_mpls.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "4.13"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "4.13",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver",
"lessThanOrEqual": "5.10.*"
},
{
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver",
"lessThanOrEqual": "7.1.*"
},
{
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"net/mpls/af_mpls.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-08-15T13:18:03.430",
"references": [
{
"url": "https://git.kernel.org/stable/c/1fea5ff0eb4aa7e951bb3d380248566c473aa377",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/248718fd88b146d8bdc7610ecd1eb4cd16e0b5a1",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/295dd295e2137e10e9a5b1891d97e0f08de76f03",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/2dc2fffc704a4365cae1aae078ba62223aaeff93",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/466b474a8deb0c93b5280c6d261e5eda6482eca7",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/95651461cf77cc6590fa08c87667717e5dcfa55d",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/a5cdd2407dd890f741f59b8367e4c6c101cce154",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/ba56f88aab18d982f2a21f11390f4d8a8897782a",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: mpls: initialize rtm_tos in mpls_getroute()\n\nmpls_getroute() builds the RTM_NEWROUTE reply to an RTM_GETROUTE\nrequest by filling a struct rtmsg allocated from an skb whose data\narea is not zeroed (alloc_skb(NLMSG_GOODSIZE, ...)). It sets every\nfield of the header except rtm_tos:\n\n\tr = nlmsg_data(nlh);\n\tr->rtm_family\t = AF_MPLS;\n\tr->rtm_dst_len\t= 20;\n\tr->rtm_src_len\t= 0;\n\tr->rtm_table\t= RT_TABLE_MAIN;\n\tr->rtm_type\t= RTN_UNICAST;\n\tr->rtm_scope\t= RT_SCOPE_UNIVERSE;\n\tr->rtm_protocol = rt->rt_protocol;\n\tr->rtm_flags\t= 0;\n\nstruct rtmsg has no padding, so the one uninitialised byte rtm_tos\n(offset 3) is copied straight to user space on recvmsg(), leaking a\nbyte of uninitialised heap memory. This is in contrast to\nmpls_dump_route(), which fills the very same header and does set\nrtm_tos = 0.\n\nInitialize rtm_tos to 0, matching mpls_dump_route().\n\nReproduced with KMSAN by adding an MPLS route and issuing a\nnon-RTM_F_FIB_MATCH RTM_GETROUTE for its label:\n\n BUG: KMSAN: kernel-infoleak in _copy_to_iter+0x36c/0x33f0\n _copy_to_iter+0x36c/0x33f0\n __skb_datagram_iter+0x196/0x12c0\n skb_copy_datagram_iter+0x5b/0x210\n netlink_recvmsg+0x37b/0xef0\n ...\n Uninit was created at:\n __alloc_skb+0x8ca/0x10e0\n mpls_getroute+0x1280/0x3a40\n rtnetlink_rcv_msg+0x1138/0x15a0\n ...\n Byte 19 of 64 is uninitialized\n\n(byte 19 = nlmsghdr(16) + rtmsg offset 3 = rtm_tos)"
}
],
"lastModified": "2026-08-19T17:21:11.870",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}