Executive brief
A vulnerability was identified in the Linux kernel's netdevsim driver, which is used for simulating network devices. The issue involves the use of uninitialized memory when building network packets for testing or simulation. While primarily affecting development and testing environments, such flaws can sometimes lead to unpredictable system behavior or minor information leaks from kernel memory.
Technical details
A vulnerability was discovered in the netdevsim driver within the Linux kernel where the 'struct iphdr' in a dummy 'sk_buff' was not properly zero-initialized. Syzbot identified a Kernel Memory Sanitizer (KMSAN) uninit-value error originating from the 'nsim_dev_trap_skb_build' function. The root cause was the use of 'skb_put' which allocates buffer space without clearing it, leaving parts of the IP header containing residual kernel memory. An attacker with local access could potentially exploit this to read uninitialized kernel memory. The fix replaces 'skb_put' with 'skb_put_zero' to ensure the entire header is zero-initialized upon allocation.
Affected products
- Linux Linux Kernel 5.4 to 6.12.y
Timeline
- 2026-04-26: disclosed: Initial patch submitted by Nikola Z. Ivanov
- 2026-06-24: advisory: CVE-2026-52985 published by NVD
References
- https://git.kernel.org/stable/c/175556c049eaec14efde8c6475e763b7579b9de7
- https://git.kernel.org/stable/c/1b7b6ae0e93b8d512e208b1378d74af052e4f4e7
- https://git.kernel.org/stable/c/35eaa6d8d6c2ee65e96f507add856e0eacf24591
- https://git.kernel.org/stable/c/6e2cfd0904976e701d7a76b86b694e72af230ab0
- https://git.kernel.org/stable/c/750d0091bebf44975421268d37484ef87060d263
- https://git.kernel.org/stable/c/818f7673ed7f4a29d4b9cee8184c47d6e57162b4
- https://git.kernel.org/stable/c/978ca6ff789f1f19c03288ac20cc1f4774e88490