Περιγραφή
In the Linux kernel, the following vulnerability has been resolved: pppoe: reload header pointer after dev_hard_header() pppoe_sendmsg() saves a pointer to the PPPoE header before calling dev_hard_header(). Device header callbacks are allowed to reallocate the skb head, invalidating pointers into it. This can happen when a send is blocked in copy_from_user() while the first non-Ethernet port is added to an empty team device. The team-s delegated GRE header callback then expands the skb head. PPPoE subsequently writes six bytes through the stale pointer into the freed head. Reload the PPPoE header through the skb-s network-header offset after device header creation. pskb_expand_head() updates that offset when it relocates the head.
EPSS 0.17500000000000002%Κίνδυνος 0
Προβολή πηγής- Δημοσίευση
- 2026-08-10 13:19:57
- Τελευταία τροποποίηση
- 2026-08-10 13:19:57
- Διάνυσμα
- Pending