← Späť na vyhľadávanie CVE

CVE-2026-53074

Linux Kernel

Popis

In the Linux kernel, the following vulnerability has been resolved: bpf: reject short IPv4/IPv6 inputs in bpf_prog_test_run_skb bpf_prog_test_run_skb() calls eth_type_trans() first and then uses skb->protocol to initialize sk family and address fields for the test run. For IPv4 and IPv6 packets, it may access ip_hdr(skb) or ipv6_hdr(skb) even when the provided test input only contains an Ethernet header. Reject the input earlier if the Ethernet frame carries IPv4/IPv6 EtherType but the L3 header is too short. Fold the IPv4/IPv6 header length checks into the existing protocol switch and return -EINVAL before accessing the network headers.

CVSS 5.5EPSS 0.11399999999999999%Riziko 0.56
Zobraziť zdroj
Zverejnené
2026-06-24 17:17:21
Dotknuté verzie
unknown
Typ
Jadro
Posledná úprava
2026-07-21 18:05:44
Vektor
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Operačné systémy
Linux