CVE-2026-74473
N/A
Summary
In the Linux kernel, the following vulnerability has been resolved:
vxlan: use pskb_network_may_pull() in route_shortcircuit()
route_shortcircuit() currently calls pskb_may_pull(skb, sizeof(struct iphdr)) (or ipv6hdr), which checks if bytes are available starting from skb->data.
However, in vxlan_xmit(), skb->data points to the MAC header, so skb_network_offset(skb) is ETH_HLEN (14 bytes). Using pskb_may_pull(skb, 20) only checks 20 bytes from skb->data (which is 14 bytes MAC header + 6 bytes of IP header), leaving the rest of the IP header potentially un-pulled in non-linear frags. Subsequent dereferences of ip_hdr(skb)->daddr can read beyond the pulled linear buffer length.
Fix this by using pskb_network_may_pull(), which adds skb_network_offset(skb) to the length check to ensure the full network header is present in the linear buffer.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | e4f67addf158f98f8197e08974966b18480dc751 < 42887be7c4cf283cce02cd0fb6411221167c8b6c | affected |
| Linux | Linux | e4f67addf158f98f8197e08974966b18480dc751 < aa0d31376d574ac858a40078431a77127bf04ee4 | affected |
| Linux | Linux | e4f67addf158f98f8197e08974966b18480dc751 < ee799977d7941dbfb11049e17edd9eaf4f8820f7 | affected |
| Linux | Linux | e4f67addf158f98f8197e08974966b18480dc751 < 4f3f96e771a20263635bb5e1307c112d613b4bbd | affected |
| Linux | Linux | e4f67addf158f98f8197e08974966b18480dc751 < 26bb2dd0a8839617e2c79ffbbe1923f8e4bab9fb | affected |
| Linux | Linux | 3.8 | affected |
| Linux | Linux | 0 < 3.8 | unaffected |
| Linux | Linux | 6.6.151 <= 6.6.* | unaffected |
| Linux | Linux | 6.12.103 <= 6.12.* | unaffected |
| Linux | Linux | 6.18.44 <= 6.18.* | unaffected |
| Linux | Linux | 7.1.8 <= 7.1.* | unaffected |
| Linux | Linux | 7.2-rc6 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/42887be7c4cf283cce02cd0fb6411221167c8b6c
- https://git.kernel.org/stable/c/aa0d31376d574ac858a40078431a77127bf04ee4
- https://git.kernel.org/stable/c/ee799977d7941dbfb11049e17edd9eaf4f8820f7
- https://git.kernel.org/stable/c/4f3f96e771a20263635bb5e1307c112d613b4bbd
- https://git.kernel.org/stable/c/26bb2dd0a8839617e2c79ffbbe1923f8e4bab9fb
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.