From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 55EBB584949 for ; Fri, 11 Sep 2026 19:56:17 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789156591; cv=none; b=GqZByLaQU+KIzZr2jbBFjeexaiCfj59AFTVR8rFV89ZNRBvCBTFP3X2CtLRfFUhlNVzB/m3fHRCKfCFHPIWLc3MoehDNwnZJPKZIVTWAWHM8KnPxGcaIWXg8YumEnJq2yRoETTrHz/sFb8arhf3JWigUykNSAuXSBTwDcA7GvXE= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789156591; c=relaxed/simple; bh=7ZFem9QsorETTkAweHU99VjlnUcunxdPli2o3ge0z0I=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=ZXa0q+S5W9yCrxoI4f3h4gFUbyhRBM/HHmKZohpCuC7PgyIDr5h2tHLcMuetZ3x532FBcP059ZLC0+tI91PjFzlMEBWTl08oh+1TXYkiNthZ4TYIsdklRXEVR+wC/QUyursHJk2HVVkGn1WXRTJyfZXtAFBm9OJ+VIc72EJGNTE= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=J2L8HILC; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="J2L8HILC" Received: by smtp.kernel.org (Postfix) with ESMTPSA id EC42A1F000FF; Fri, 11 Sep 2026 19:56:13 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1789156574; bh=RDYQ1Ut0c1AOb5sV+Oi1aTjdj/uAGm6UlQVNF7FGlbA=; h=From:To:Cc:Subject:Date:Reply-To; b=J2L8HILCwQlBx8ollXWZHni9dTDrT8e/zUasZkmhjnGJMwzBug3/fGE+jIIQp9jjA Cwnn6NdihbV6UhhiAsAI38N8i2/Vmeb2ZkdmxmdgoykwKHPFqI5D5VjzPf15k4SDLl 0sK6V31rdVEru6WZ0/kr2ufkT3bEQsUfNV2eU8Hc= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-89563: ip6_tunnel: use skb_cow_head() in ip6_tnl_xmit() Date: Fri, 11 Sep 2026 21:44:12 +0200 Message-ID: <2026091124-CVE-2026-89563-7028@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=3477; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=PdBzb+v7IWE4sOBL881J/3f942KbcMi3l1HbphK+dZE=; b=owGbwMvMwCRo6H6F97bub03G02pJDFlLIlNu/5ok5hLps3Lpx3Te4Ak+O0vmfEmQF2PM0Tqpv 57lJkdlRywLgyATg6yYIsuXbTxH91ccUvQytD0NM4eVCWQIAxenAEykdB3DHL719xs3eLs1Ttqk Prk+/Ybhz277coYFuw/PuNt0ddXhKU9X/46cyx119MPEowA= X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: ip6_tunnel: use skb_cow_head() in ip6_tnl_xmit() ip6_tnl_xmit() may need to expand headroom before it can push the outer IPv6 and optional encap headers. It currently does that with skb_realloc_headroom(), copies skb->sk ownership, consumes the original skb, and then continues processing with the replacement skb kept only in its local variable. That is safe only if the helper cannot fail afterwards. But this helper still has post-reallocation error exits. collect_md tunnels reject non-NONE encap after the replacement, and ip6_tnl_encap() can also fail later. In those cases the helper returns an error to its callers while the caller still only has the original skb pointer. Both ip6_tnl_start_xmit() and the IPv6 GRE paths free the caller skb on error, so they can end up freeing an skb that ip6_tnl_xmit() already consumed. Use skb_cow_head() instead. It provides the required headroom and writability without privately replacing the caller-owned skb, so later error returns cannot leave callers with a stale pointer. The Ethernet users, ip6gretap and ip6erspan, clear IFF_TX_SKB_SHARING and already call skb_cow_head() before entering ip6_tnl_xmit(). They do not rely on the removed skb_shared() reallocation. This also makes the IPv6 tunnel path consistent with ip_tunnel_xmit(). The Linux kernel CVE team has assigned CVE-2026-89563 to this issue. Affected and fixed versions =========================== Issue introduced in 4.7 with commit 058214a4d1dfefed9f01a277fadd3590acb5f990 and fixed in 6.12.109 with commit 37df5bc6b5ccad88c2faa0f5466f150178882b74 Issue introduced in 4.7 with commit 058214a4d1dfefed9f01a277fadd3590acb5f990 and fixed in 6.18.50 with commit b36dfd6e8cff00cea81c11cc0af88d1564763461 Issue introduced in 4.7 with commit 058214a4d1dfefed9f01a277fadd3590acb5f990 and fixed in 7.2.4 with commit 8fc56ca49fc0ee1725b55c67bb43ab0dd01f3f52 Issue introduced in 4.7 with commit 058214a4d1dfefed9f01a277fadd3590acb5f990 and fixed in 7.3-rc1 with commit 87f21b59ddc618eff9670c174842964ad65fdade Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-89563 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: net/ipv6/ip6_tunnel.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/37df5bc6b5ccad88c2faa0f5466f150178882b74 https://git.kernel.org/stable/c/b36dfd6e8cff00cea81c11cc0af88d1564763461 https://git.kernel.org/stable/c/8fc56ca49fc0ee1725b55c67bb43ab0dd01f3f52 https://git.kernel.org/stable/c/87f21b59ddc618eff9670c174842964ad65fdade