Executive brief
A vulnerability in the Linux kernel's networking subsystem could allow for incorrect network traffic analysis. The issue affects the Passive OS Fingerprinting (OSF) module, which is used to identify the operating systems of remote devices based on their network packets. If exploited, this could lead to incorrect security logging or the bypass of certain network filtering rules that rely on OS identification.
Technical details
An out-of-bounds read exists in nf_osf_match() within net/netfilter/nfnetlink_osf.c. The nf_osf_hdr_ctx structure is initialized once and passed by reference to nf_osf_match_one() for fingerprint checking. During TCP option parsing, nf_osf_match_one() advances a shared ctx->optp pointer but fails to restore it if a match is found and NF_OSF_LOGLEVEL_ALL is enabled. Subsequent fingerprint checks then begin parsing from the end of the options buffer, leading to reads of uninitialized or 'garbage' data. This can result in incorrect OS matching or logging failures. The fix makes nf_osf_match_one() stateless by using a local pointer for traversal.
Affected products
- Linux Linux Kernel 1a6a0951fc00 to f5ca450087c3baf3651055e7a6de92600f827af3
Timeline
- 2026-04-17: other: Patch authored
- 2026-06-01: patched: Patch committed to stable trees
- 2026-06-24: disclosed: CVE published
References
- https://git.kernel.org/stable/c/0145548346c4a30981a870a8ca00eac46ba27e85
- https://git.kernel.org/stable/c/1c136f2c44a5913646bac85303612fd0825197a0
- https://git.kernel.org/stable/c/1e19a07291bb8682c14c39a64725a3ae54ab8ccc
- https://git.kernel.org/stable/c/21883587593d7c8bb519a79460a0b5bc5ffbdabd
- https://git.kernel.org/stable/c/32e50f92c7cf3f4eba29622179a5fcdc2aebab41
- https://git.kernel.org/stable/c/70a3f31d25cf2ec9d4ddfa408120171ead955623
- https://git.kernel.org/stable/c/edb78a142d2e5948e63647c0646aa7e7886935f0