« Volver al listado

CVE-2026-74659

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

net: bridge: mrp: fix uninitialised bytes on the wire

br_mrp_alloc_test_skb() builds MRP test frames on an skb from dev_alloc_skb(), which does not clear the linear data area. On the MRA ring-role branch the sub-option TLV header is appended with

so sub_tlv->length is never written, and the two trailing alignment bytes are appended with a bare skb_put() that does not clear them either. The neighbouring oui and sub_opt regions are explicitly zeroed, so three uninitialised bytes are left in every MRA MRP_Test frame that goes out.

Leer descripción completaMostrar menos

Put the sub-option TLV header and the alignment padding in a single skb_put_zero(), which clears both. The AUTO_MGR sub-TLV carries no payload, so the zeroed length field is already the value it should have.

Detalles técnicos trazas, registros y código del informe original
	sub_tlv = skb_put(skb, sizeof(*sub_tlv));
	sub_tlv->type = BR_MRP_SUB_TLV_HEADER_TEST_AUTO_MGR;

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-74659",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "f7458934b0791c39a001e4d902fc3bf697b439b5",
              "lessThan": "014c062d23c63ec77ef2cf17a0d9363c7441cc94",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f7458934b0791c39a001e4d902fc3bf697b439b5",
              "lessThan": "7ebc23ff03668042e0b0e4034bb1518d36198d9e",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f7458934b0791c39a001e4d902fc3bf697b439b5",
              "lessThan": "06d58b8d2f053ced82e01efaeb6e7c82891eed58",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f7458934b0791c39a001e4d902fc3bf697b439b5",
              "lessThan": "a5e385eeb2d6dbbbdebfa050e67c34734ae12693",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f7458934b0791c39a001e4d902fc3bf697b439b5",
              "lessThan": "5912cf1822fbe53ae275c147868740eb384a5d3e",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f7458934b0791c39a001e4d902fc3bf697b439b5",
              "lessThan": "e08665218040f8e312abe40f74543186f3c2c941",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f7458934b0791c39a001e4d902fc3bf697b439b5",
              "lessThan": "63488dba65ef91373ef616575b32eb0eb21459f4",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "net/bridge/br_mrp.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.14"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.14",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.15.216",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.183",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.152",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.104",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.45",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.9",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "net/bridge/br_mrp.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-08-22T16:16:39.613",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/014c062d23c63ec77ef2cf17a0d9363c7441cc94",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/06d58b8d2f053ced82e01efaeb6e7c82891eed58",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/5912cf1822fbe53ae275c147868740eb384a5d3e",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/63488dba65ef91373ef616575b32eb0eb21459f4",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/7ebc23ff03668042e0b0e4034bb1518d36198d9e",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/a5e385eeb2d6dbbbdebfa050e67c34734ae12693",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/e08665218040f8e312abe40f74543186f3c2c941",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: bridge: mrp: fix uninitialised bytes on the wire\n\nbr_mrp_alloc_test_skb() builds MRP test frames on an skb from\ndev_alloc_skb(), which does not clear the linear data area.  On the MRA\nring-role branch the sub-option TLV header is appended with\n\n\tsub_tlv = skb_put(skb, sizeof(*sub_tlv));\n\tsub_tlv->type = BR_MRP_SUB_TLV_HEADER_TEST_AUTO_MGR;\n\nso sub_tlv->length is never written, and the two trailing alignment bytes\nare appended with a bare skb_put() that does not clear them either.  The\nneighbouring oui and sub_opt regions are explicitly zeroed, so three\nuninitialised bytes are left in every MRA MRP_Test frame that goes out.\n\nPut the sub-option TLV header and the alignment padding in a single\nskb_put_zero(), which clears both.  The AUTO_MGR sub-TLV carries no\npayload, so the zeroed length field is already the value it should have."
    }
  ],
  "lastModified": "2026-08-22T16:16:39.613",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}