From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id BB7163905E7 for ; Wed, 24 Jun 2026 07:16:24 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1782285385; cv=none; b=aw3Ig9a+4VU2Udti0JC67/Gmgt1wt1VGc8ixrgfnUgMh/G1JX4h96h9BsriMvhpf4hM0zZe5Q/RBg8pFxozkVI3kkFkGXYm5Eu997qJ4V05A6aLKPfRrpONN5yyYgGb0BuwU0ej1Jixl5zP615hmUR1832ad2uz9kA965AUikxY= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1782285385; c=relaxed/simple; bh=XOkiaZYLh6hzU4ODXHpQlYj3hcWLocX3M5gYpkWvnlo=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=WG2F0eGhikWUSS6hLGx2/T3ne7xGcD/GZnghghC1XozY83pSxS/uD2pNb6Uitbnd8RRpZ4/CZNkKhFL2E8p3M48CzftlS6proeNvjFwTCMxJd+vdnz0kGxTNNdkLaDoRFpslyEfWewSkB/ExNwiw2wqMcuN6Lvrf80r9pVSdVrY= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=ZVtiyCJQ; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="ZVtiyCJQ" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 00C691F000E9; Wed, 24 Jun 2026 07:16:23 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1782285384; bh=QIgosXFmMVyE1PRUwXJ8rq0AUXLK8XMJFWepKU6V3HU=; h=From:To:Cc:Subject:Date:Reply-To; b=ZVtiyCJQSjiBgAuS973sCxwnwV0BvVWX6NpkWf8c2EAZwRdR1i4LYN5KD8Pq1gv4E pyNlKtiLYLmeH086AweSAZvD3KoHq+hQorKuhCoyKg9fn/s3fNdCleo27Bz8XLSwRA OIgnZ41zbtFAtgijKSsmyRiVAA3SetpobMlTEn3w= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-52942: netfilter: nf_log: validate MAC header was set before dumping it Date: Wed, 24 Jun 2026 09:13:57 +0200 Message-ID: <2026062435-CVE-2026-52942-2530@gregkh> X-Mailer: git-send-email 2.54.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=4639; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=r6ytTjMMGMG3TdlkdIGCamKPD8LKXXXaS3JpEauxj6g=; b=owGbwMvMwCRo6H6F97bub03G02pJDFnWzfPDmOYeE//8aOJrORe27aZHGG0ebGjKKbyh198w9 ey2pQIPOmJZGASZGGTFFFm+bOM5ur/ikKKXoe1pmDmsTCBDGLg4BWAiAo4M82O1pRXO/JjR80df r6vyU9msgJy65QwL1m+qE2PnXXz98spbKZurFV72Lv/vCgA= X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_log: validate MAC header was set before dumping it The fallback path of dump_mac_header() guards the MAC header access only with "skb->mac_header != skb->network_header", without checking skb_mac_header_was_set(). When the MAC header is unset, mac_header is 0xffff, so the test passes and skb_mac_header(skb) returns skb->head + 0xffff, ~64 KiB past the buffer; the loop then reads dev->hard_header_len bytes out of bounds into the kernel log. This is reachable via the netdev logger: nf_log_unknown_packet() calls dump_mac_header() unconditionally, and an skb sent through AF_PACKET with PACKET_QDISC_BYPASS reaches the egress hook with mac_header still unset (__dev_queue_xmit(), which would reset it, is bypassed). Add the skb_mac_header_was_set() check the ARPHRD_ETHER path already uses, and replace the open-coded MAC header length test with skb_mac_header_len(). Only skbs with an unset MAC header are affected; valid ones are dumped as before. BUG: KASAN: slab-out-of-bounds in dump_mac_header (net/netfilter/nf_log_syslog.c:831) Read of size 1 at addr ffff88800ea49d3f by task exploit/148 Call Trace: kasan_report (mm/kasan/report.c:595) dump_mac_header (net/netfilter/nf_log_syslog.c:831) nf_log_netdev_packet (net/netfilter/nf_log_syslog.c:938 net/netfilter/nf_log_syslog.c:963) nf_log_packet (net/netfilter/nf_log.c:260) nft_log_eval (net/netfilter/nft_log.c:60) nft_do_chain (net/netfilter/nf_tables_core.c:285) nft_do_chain_netdev (net/netfilter/nft_chain_filter.c:307) nf_hook_slow (net/netfilter/core.c:619) nf_hook_direct_egress (net/packet/af_packet.c:257) packet_xmit (net/packet/af_packet.c:280) packet_sendmsg (net/packet/af_packet.c:3114) __sys_sendto (net/socket.c:2265) The Linux kernel CVE team has assigned CVE-2026-52942 to this issue. Affected and fixed versions =========================== Issue introduced in 2.6.36 with commit 7eb9282cd0efac08b8377cbd5037ba297c77e3f7 and fixed in 5.15.210 with commit d704ee9c7bc68a161684c51a7ac05b446dcf38d4 Issue introduced in 2.6.36 with commit 7eb9282cd0efac08b8377cbd5037ba297c77e3f7 and fixed in 6.1.176 with commit befb8968a2abdfa948d5600ea7f7a509a292a590 Issue introduced in 2.6.36 with commit 7eb9282cd0efac08b8377cbd5037ba297c77e3f7 and fixed in 6.6.143 with commit 8a81e336da685423f5b64aac4d571e63d674c52a Issue introduced in 2.6.36 with commit 7eb9282cd0efac08b8377cbd5037ba297c77e3f7 and fixed in 6.12.94 with commit c38d41134085193efd5b237cf513ad5b3421a60d Issue introduced in 2.6.36 with commit 7eb9282cd0efac08b8377cbd5037ba297c77e3f7 and fixed in 6.18.36 with commit af1b7699466f6556b351fa25d3dc870abfb5d310 Issue introduced in 2.6.36 with commit 7eb9282cd0efac08b8377cbd5037ba297c77e3f7 and fixed in 7.0.13 with commit 65ef7397eb9a296e91839f5fd10be96f23d332e7 Issue introduced in 2.6.36 with commit 7eb9282cd0efac08b8377cbd5037ba297c77e3f7 and fixed in 7.1 with commit a84b6fedbc97078788be78dbdd7517d143ad1a77 Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-52942 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: net/netfilter/nf_log_syslog.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/d704ee9c7bc68a161684c51a7ac05b446dcf38d4 https://git.kernel.org/stable/c/befb8968a2abdfa948d5600ea7f7a509a292a590 https://git.kernel.org/stable/c/8a81e336da685423f5b64aac4d571e63d674c52a https://git.kernel.org/stable/c/c38d41134085193efd5b237cf513ad5b3421a60d https://git.kernel.org/stable/c/af1b7699466f6556b351fa25d3dc870abfb5d310 https://git.kernel.org/stable/c/65ef7397eb9a296e91839f5fd10be96f23d332e7 https://git.kernel.org/stable/c/a84b6fedbc97078788be78dbdd7517d143ad1a77