目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2026-98158— Linux ppp_async 丢弃错误帧而非重置其头部空间漏洞

一分钟漏洞结论

影响对象
Linux Linux
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

在 Linux 内核中,已修复以下漏洞: ppp_async:丢弃出错帧,而不是重置其 headroom(头部预留空间) 在运行 pass/active BPF 过滤器之前,会在 skb 前 prepends(前置)一个两字节的方向标签: 在接收路径上,没有任何内容能保证这两个字节的 headroom 存在。 中 的帧错误处理路径会将被重用的 skb 的 headroom 重置为零,同时声称将其恢复到全新分配的状态——但实际上,从 获取的新 skb 会携带 预留空间: 仍指向该 skb,因此下一帧将被重新组装到其中

AI 预测 7.5 利用难度: 较易 EPSS 0.16% · P5

可能的 ATT&CK 技术 1 AI

T1498 · Network Denial of Service

影响版本矩阵 18

厂商产品 版本范围状态
Linux Linux 6722e78c90054101e6797d5944cdc81af9897a0a< 25f354c55b8435d1f51b8a0a05a3cfe429358523 affected
6722e78c90054101e6797d5944cdc81af9897a0a< a86a17745c3e1c6fadd4d6e90c03552dfe531c8c affected
6722e78c90054101e6797d5944cdc81af9897a0a< ff035780adb0f49dc2c7ada26b4697849a68bec8 affected
6722e78c90054101e6797d5944cdc81af9897a0a< c4bb894362d224b699e2f95c6c26707d9654e4a3 affected
6722e78c90054101e6797d5944cdc81af9897a0a< d0fc3dabfe67caf084e7119ceb2ee23f5ad2f2da affected
6722e78c90054101e6797d5944cdc81af9897a0a< 0c53eb14975f029abd6b26896a460f0d2aaefe6b affected
6722e78c90054101e6797d5944cdc81af9897a0a< 717137221c7d90e7c98bda9a370c9da6cbf015e5 affected
6722e78c90054101e6797d5944cdc81af9897a0a< 8dc5d98a16fa23c00999aecf10018c9f69fa5bf4 affected
… +10 条更多
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2026-98158 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
ppp_async: drop the errored frame instead of resetting its headroom
来源: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: ppp_async: drop the errored frame instead of resetting its headroom ppp_receive_nonmp_frame() prepends a two-byte direction tag before running the pass/active BPF filters: *(__be16 *)skb_push(skb, 2) = htons(PPP_FILTER_INBOUND_TAG); Nothing on the receive path guarantees those two bytes of headroom. The frame-error path in ppp_async's process_input_packet() resets a reused skb's headroom to zero while claiming to restore it to a freshly allocated state - but a fresh skb from dev_alloc_skb() carries NET_SKB_PAD: err: if (skb) { /* make skb appear as freshly allocated */ skb_trim(skb, 0); skb_reserve(skb, - skb_headroom(skb)); } ap->rpkt still points at that skb, so the next frame is reassembled into it with no headroom at all. A peer that sends a bad-FCS frame followed by one beginning ff 03 then leaves a single byte of headroom by the time the filter tag is pushed, which lands one byte below skb->head: skbuff: skb_under_panic: len:49 put:2 head:ffff888003c10000 data:ffff888003c0ffff tail:0x30 end:0x640 dev:<NULL> kernel BUG at net/core/skbuff.c:214! RIP: 0010:skb_panic+0x13e/0x230 Call Trace: skb_push+0xbd/0x100 ppp_receive_nonmp_frame+0x48a/0x1d10 ppp_input+0x4e9/0x2f80 ppp_async_process+0x2a/0xe0 tasklet_action_common+0x20f/0x8a0 handle_softirqs+0x18e/0x590 Kernel panic - not syncing: Fatal exception in interrupt Zeroing the headroom violates the NET_SKB_PAD guarantee that dev_alloc_skb() gives the rest of the receive path. Besides the filter panic above, when CCP compression is enabled ppp_decompress_frame() hands skb->data - 2 to ->decompress()/->incomp(), which then reads out of bounds before skb->head for the same reason. Rather than restore the headroom, drop the errored frame - as ppp_synctty already does on its error path - and clear ap->rpkt so the next frame is reassembled into a fresh skb with proper headroom. This is simpler and fixes both the filter under-panic and the CCP out-of-bounds read. The original V1 of this patch made room in ppp_receive_nonmp_frame() with skb_cow_head(); Eric pointed out that fixing the root cause in the transport is the right approach. Found by fuzzing the PPP receive path with a mutating peer on a pty; it is an interesting (remote) DoS: root configures PPP, the peer supplies two crashing frames. The reproducer (repro-ppp-skb.c, unchanged from v1) panics in about a second, and returns cleanly with this applied.
来源: CVE Program / CVE List V5
CVSS Information
N/A
来源: CVE Program / CVE List V5
Vulnerability Type
N/A
来源: CVE Program / CVE List V5

受影响产品

厂商 产品 影响版本 CPE 订阅
Linux Linux 6722e78c90054101e6797d5944cdc81af9897a0a ~ 25f354c55b8435d1f51b8a0a05a3cfe429358523 -
Linux Linux 2.6.15 -

二、漏洞 CVE-2026-98158 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-98158 的情报信息

请登录查看更多情报信息。

CVE-2026-98158 补丁与修复 (8)

同批安全公告 · Linux · 2026-09-25 · 共 372 条

CVE-2026-100075 9.8 CRITICAL RDMA/srpt:srpt_alloc_rw_ctxs() 未释放计数器修复
CVE-2026-97555 8.8 HIGH smb客户端:修复DACL所有者/组重写中的堆溢出漏洞
CVE-2026-97957 8.8 HIGH hinic 邮箱段缓冲区溢出漏洞
CVE-2026-97527 8.8 HIGH qla2xxx SCSI驱动程序 NVMe未解决上下文列表竞争条件漏洞
CVE-2026-97528 8.8 HIGH QLogic qla2xxx驱动LS拒绝错误NVMe内存泄漏漏洞
CVE-2026-98115 8.8 HIGH ksmbd 注销期间会话安全排空漏洞
CVE-2026-97525 8.2 HIGH x86/mm/pat:内核页表分裂页表分配漏洞
CVE-2026-98069 8.1 HIGH Net/RDS rds_conn_shutdown() 快速路径锁获取漏洞
CVE-2026-97573 8.1 HIGH bnxt_en 驱动 bnxt_rx_ring_reset 缓冲区分配失败漏洞
CVE-2026-97570 8.1 HIGH bnxt_en: 修复因SW TPA ID绑定问题导致的崩溃漏洞
CVE-2026-98130 8.1 HIGH SCTP定时器启动竞争条件漏洞
CVE-2026-98070 8.1 HIGH Linux RDS 模块远程代码执行漏洞
CVE-2026-98122 7.8 HIGH Linux内核vxlan mdb远程源删除后使用漏洞
CVE-2026-97575 7.8 HIGH v4l2-ctrls AV1瓦片计数验证漏洞
CVE-2026-97576 7.8 HIGH V4L2-ctrls HEVC 瓦片计数验证漏洞
CVE-2026-97941 7.8 HIGH Linux 内核 slab 内存分配器竞态条件漏洞
CVE-2026-98112 7.8 HIGH ksmbd 网络接口事件中监听器任务生命周期修复漏洞
CVE-2026-98116 7.8 HIGH ALSA: PCM内存映射与缓冲区重新分配序列化以修复页面UAF漏洞
CVE-2026-97580 7.8 HIGH rkvdec HEVC解析数组越界漏洞
CVE-2026-97940 7.8 HIGH IPv6 修复 fib6 遍历器在 seq 停止时存在 UAF 漏洞

显示前 20 条,共 372 条。 查看全部 &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-98158

暂无评论


发表评论