All of lore.kernel.org
 help / color / mirror / Atom feed
* CVE-2026-72399: net: enetc: check the number of BDs needed for xdp_frame
@ 2026-08-15  6:07 Greg Kroah-Hartman
  0 siblings, 0 replies; only message in thread
From: Greg Kroah-Hartman @ 2026-08-15  6:07 UTC (permalink / raw)
  To: linux-cve-announce; +Cc: Greg Kroah-Hartman

From: Greg Kroah-Hartman <gregkh@kernel.org>

Description
===========

In the Linux kernel, the following vulnerability has been resolved:

net: enetc: check the number of BDs needed for xdp_frame

The size of xdp_redirect_arr array is ENETC_MAX_SKB_FRAGS. However, the
number of fragments contained in xdp_frame may be greater than or equal
to ENETC_MAX_SKB_FRAGS, which will cause the access to xdp_redirect_arr
to be out of bounds.

The Linux kernel CVE team has assigned CVE-2026-72399 to this issue.


Affected and fixed versions
===========================

	Issue introduced in 5.13 with commit 9d2b68cc108db2fdb35022ed2d88cfb305c441a6 and fixed in 6.1.178 with commit 1ecb199b0e6d12ab6c26c0b7edf1a8f4472d9aed
	Issue introduced in 5.13 with commit 9d2b68cc108db2fdb35022ed2d88cfb305c441a6 and fixed in 6.6.145 with commit f55276160ffad3e235b657ee4b7304eb99b90e5c
	Issue introduced in 5.13 with commit 9d2b68cc108db2fdb35022ed2d88cfb305c441a6 and fixed in 6.12.97 with commit cfbc6e9b84dcc0aa2d65c84ea4745af327763209
	Issue introduced in 5.13 with commit 9d2b68cc108db2fdb35022ed2d88cfb305c441a6 and fixed in 6.18.40 with commit 1681cc7974a6123f5d5740b03bc11e4784bd2542
	Issue introduced in 5.13 with commit 9d2b68cc108db2fdb35022ed2d88cfb305c441a6 and fixed in 7.1.5 with commit d22829101ab675607ad6c3d420fb3ab875f46bbb
	Issue introduced in 5.13 with commit 9d2b68cc108db2fdb35022ed2d88cfb305c441a6 and fixed in 7.2-rc2 with commit 555c5475e787802eeae0d2b91c2f66c330db2767

Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.

Unaffected versions might change over time as fixes are backported to
older supported kernel versions.  The official CVE entry at
	https://cve.org/CVERecord/?id=CVE-2026-72399
will be updated if fixes are backported, please check that for the most
up to date information about this issue.


Affected files
==============

The file(s) affected by this issue are:
	drivers/net/ethernet/freescale/enetc/enetc.c


Mitigation
==========

The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes.  Individual
changes are never tested alone, but rather are part of a larger kernel
release.  Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all.  If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
	https://git.kernel.org/stable/c/1ecb199b0e6d12ab6c26c0b7edf1a8f4472d9aed
	https://git.kernel.org/stable/c/f55276160ffad3e235b657ee4b7304eb99b90e5c
	https://git.kernel.org/stable/c/cfbc6e9b84dcc0aa2d65c84ea4745af327763209
	https://git.kernel.org/stable/c/1681cc7974a6123f5d5740b03bc11e4784bd2542
	https://git.kernel.org/stable/c/d22829101ab675607ad6c3d420fb3ab875f46bbb
	https://git.kernel.org/stable/c/555c5475e787802eeae0d2b91c2f66c330db2767

^ permalink raw reply	[flat|nested] only message in thread

only message in thread, other threads:[~2026-08-15  6:26 UTC | newest]

Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-15  6:07 CVE-2026-72399: net: enetc: check the number of BDs needed for xdp_frame Greg Kroah-Hartman

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.