Executive brief
A vulnerability was identified in the Linux kernel's Open vSwitch component, which manages network traffic between virtual machines and physical networks. A local attacker could exploit a flaw in how the system processes specific network headers (NSH) to cause a system crash or potentially access sensitive kernel memory. This issue primarily impacts the stability and confidentiality of the host operating system.
Technical details
The vulnerability is a slab-out-of-bounds read within the Open vSwitch (OVS) module, specifically in the push_nsh() action handling. The root cause is a lack of validation for the 'middle' attribute (OVS_KEY_ATTR_NSH) in the nested Netlink structure OVS_ACTION_ATTR_PUSH_NSH(OVS_KEY_ATTR_NSH(...)). While the outermost and innermost attributes were validated, the middle attribute was unwrapped using nla_data() without checking its type or length. An attacker providing a malformed Netlink message with an incorrect attribute size can trigger an out-of-bounds access during action execution when the buffer is allocated to an exact size. This has been fixed by adding explicit checks to ensure the middle attribute is correctly typed and sized.
Affected products
- Linux Linux Kernel b2d0f5d5dc53 to d0c135b8bbbcf92836068fd395bebeb7ae6c7bef (6.12.y)
- Linux Linux Kernel b2d0f5d5dc53 to 3bc2efff20a38b2c7ca18317649715df0dd62ced (6.11.y)
- Linux Linux Kernel b2d0f5d5dc53 to 1b569db9c2f28b599e40050524aae5f7332bc294 (6.6.y)
- Linux Linux Kernel b2d0f5d5dc53 to 10ffc558246f2c75619aedda0921906095e46702 (6.1.y)
- Linux Linux Kernel b2d0f5d5dc53 to 2ecfc4433acdb149eafd7fb22d7fd4adf90b25e9 (5.15.y)
- Linux Linux Kernel b2d0f5d5dc53 to c999153bfb2d1d9b295b7010d920f2a7c6d7595f (5.10.y)
- Linux Linux Kernel b2d0f5d5dc53 to 5ace7ef87f059d68b5f50837ef3e8a1a4870c36e (mainline)
Timeline
- 2025-12-04: disclosed: Initial patch submitted by Ilya Maximets
- 2026-01-11: patched: Patches merged into various stable kernel branches
- 2026-01-13: advisory: CVE published
References
- https://git.kernel.org/stable/c/10ffc558246f2c75619aedda0921906095e46702
- https://git.kernel.org/stable/c/1b569db9c2f28b599e40050524aae5f7332bc294
- https://git.kernel.org/stable/c/2ecfc4433acdb149eafd7fb22d7fd4adf90b25e9
- https://git.kernel.org/stable/c/3bc2efff20a38b2c7ca18317649715df0dd62ced
- https://git.kernel.org/stable/c/5ace7ef87f059d68b5f50837ef3e8a1a4870c36e
- https://git.kernel.org/stable/c/c999153bfb2d1d9b295b7010d920f2a7c6d7595f
- https://git.kernel.org/stable/c/d0c135b8bbbcf92836068fd395bebeb7ae6c7bef