Linux kernel CVE announcements
 help / color / mirror / Atom feed
* CVE-2026-52942: netfilter: nf_log: validate MAC header was set before dumping it
@ 2026-06-24  7:13 Greg Kroah-Hartman
  0 siblings, 0 replies; only message in thread
From: Greg Kroah-Hartman @ 2026-06-24  7:13 UTC (permalink / raw)
  To: linux-cve-announce; +Cc: Greg Kroah-Hartman

From: Greg Kroah-Hartman <gregkh@kernel.org>

Description
===========

In the Linux kernel, the following vulnerability has been resolved:

netfilter: nf_log: validate MAC header was set before dumping it

The fallback path of dump_mac_header() guards the MAC header access
only with "skb->mac_header != skb->network_header", without checking
skb_mac_header_was_set(). When the MAC header is unset, mac_header is
0xffff, so the test passes and skb_mac_header(skb) returns
skb->head + 0xffff, ~64 KiB past the buffer; the loop then reads
dev->hard_header_len bytes out of bounds into the kernel log.

This is reachable via the netdev logger: nf_log_unknown_packet() calls
dump_mac_header() unconditionally, and an skb sent through AF_PACKET
with PACKET_QDISC_BYPASS reaches the egress hook with mac_header still
unset (__dev_queue_xmit(), which would reset it, is bypassed).

Add the skb_mac_header_was_set() check the ARPHRD_ETHER path already
uses, and replace the open-coded MAC header length test with
skb_mac_header_len(). Only skbs with an unset MAC header are affected;
valid ones are dumped as before.

 BUG: KASAN: slab-out-of-bounds in dump_mac_header (net/netfilter/nf_log_syslog.c:831)
 Read of size 1 at addr ffff88800ea49d3f by task exploit/148
 Call Trace:
  kasan_report (mm/kasan/report.c:595)
  dump_mac_header (net/netfilter/nf_log_syslog.c:831)
  nf_log_netdev_packet (net/netfilter/nf_log_syslog.c:938 net/netfilter/nf_log_syslog.c:963)
  nf_log_packet (net/netfilter/nf_log.c:260)
  nft_log_eval (net/netfilter/nft_log.c:60)
  nft_do_chain (net/netfilter/nf_tables_core.c:285)
  nft_do_chain_netdev (net/netfilter/nft_chain_filter.c:307)
  nf_hook_slow (net/netfilter/core.c:619)
  nf_hook_direct_egress (net/packet/af_packet.c:257)
  packet_xmit (net/packet/af_packet.c:280)
  packet_sendmsg (net/packet/af_packet.c:3114)
  __sys_sendto (net/socket.c:2265)

The Linux kernel CVE team has assigned CVE-2026-52942 to this issue.


Affected and fixed versions
===========================

	Issue introduced in 2.6.36 with commit 7eb9282cd0efac08b8377cbd5037ba297c77e3f7 and fixed in 5.15.210 with commit d704ee9c7bc68a161684c51a7ac05b446dcf38d4
	Issue introduced in 2.6.36 with commit 7eb9282cd0efac08b8377cbd5037ba297c77e3f7 and fixed in 6.1.176 with commit befb8968a2abdfa948d5600ea7f7a509a292a590
	Issue introduced in 2.6.36 with commit 7eb9282cd0efac08b8377cbd5037ba297c77e3f7 and fixed in 6.6.143 with commit 8a81e336da685423f5b64aac4d571e63d674c52a
	Issue introduced in 2.6.36 with commit 7eb9282cd0efac08b8377cbd5037ba297c77e3f7 and fixed in 6.12.94 with commit c38d41134085193efd5b237cf513ad5b3421a60d
	Issue introduced in 2.6.36 with commit 7eb9282cd0efac08b8377cbd5037ba297c77e3f7 and fixed in 6.18.36 with commit af1b7699466f6556b351fa25d3dc870abfb5d310
	Issue introduced in 2.6.36 with commit 7eb9282cd0efac08b8377cbd5037ba297c77e3f7 and fixed in 7.0.13 with commit 65ef7397eb9a296e91839f5fd10be96f23d332e7
	Issue introduced in 2.6.36 with commit 7eb9282cd0efac08b8377cbd5037ba297c77e3f7 and fixed in 7.1 with commit a84b6fedbc97078788be78dbdd7517d143ad1a77

Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.

Unaffected versions might change over time as fixes are backported to
older supported kernel versions.  The official CVE entry at
	https://cve.org/CVERecord/?id=CVE-2026-52942
will be updated if fixes are backported, please check that for the most
up to date information about this issue.


Affected files
==============

The file(s) affected by this issue are:
	net/netfilter/nf_log_syslog.c


Mitigation
==========

The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes.  Individual
changes are never tested alone, but rather are part of a larger kernel
release.  Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all.  If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
	https://git.kernel.org/stable/c/d704ee9c7bc68a161684c51a7ac05b446dcf38d4
	https://git.kernel.org/stable/c/befb8968a2abdfa948d5600ea7f7a509a292a590
	https://git.kernel.org/stable/c/8a81e336da685423f5b64aac4d571e63d674c52a
	https://git.kernel.org/stable/c/c38d41134085193efd5b237cf513ad5b3421a60d
	https://git.kernel.org/stable/c/af1b7699466f6556b351fa25d3dc870abfb5d310
	https://git.kernel.org/stable/c/65ef7397eb9a296e91839f5fd10be96f23d332e7
	https://git.kernel.org/stable/c/a84b6fedbc97078788be78dbdd7517d143ad1a77

^ permalink raw reply	[flat|nested] only message in thread

only message in thread, other threads:[~2026-06-24  7:16 UTC | newest]

Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-06-24  7:13 CVE-2026-52942: netfilter: nf_log: validate MAC header was set before dumping it Greg Kroah-Hartman

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox