Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-98375— xen/netfront: drop RX packets with a short Ethernet header

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Linux 内核中,已修复以下漏洞: xen/netfront:丢弃以太网头过短的 RX(接收)数据包 在处理入队数据时, 函数会先将 字节的数据拷贝到缓冲区头部,然后再调用 函数。其中, 的值等于第一个 RX 槽位(slot)的长度,并受 上限限制,该长度来自后端(backend)提供。然而,代码中并未将此长度与 (以太网头最小长度)进行比较验证。 如果第一个槽位短于 且后续还有更多槽位,则缓冲区头部长度将不足一个以太网头的长度,而 (套接字缓冲区总长度)却更长,从而导致 在调用 时触发 BUG(内核断言失败

AI Predicted 5.5 Difficulty: Moderate
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-98375

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
xen/netfront: drop RX packets with a short Ethernet header
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: xen/netfront: drop RX packets with a short Ethernet header handle_incoming_queue() pulls pull_to bytes into the head before calling eth_type_trans(). pull_to is the length of the first RX slot, capped at RX_COPY_THRESHOLD, and that length comes from the backend. Nothing checks it against ETH_HLEN. If the first slot is shorter than ETH_HLEN and more slots follow, the head ends up shorter than an Ethernet header while skb->len is longer, and eth_type_trans() BUG()s in __skb_pull(). If the whole packet is shorter than ETH_HLEN, eth_type_trans() reads the header past the end of the data instead. Pull at least ETH_HLEN, and drop the packet if that fails, which also drops packets too short to hold an Ethernet header. This also checks the return value of the pull, which was ignored.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 0d160211965b79de989cf2d170985abeb8da5ec6 ~ 089e58805c452e52179482b1025a8e309a57f801 -
Linux Linux 2.6.23 -

II. Public POCs for CVE-2026-98375

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-98375

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-98375 (1)

Same Patch Batch · Linux · 2026-10-09 · 10 CVEs total

CVE-2026-98384 bpf: Fix out-of-bounds read of sk_protocol in bpf_sock_destroy()
CVE-2026-98383 bpf: Disallow bpf_skb_pull_data() for LWT_SEG6LOCAL
CVE-2026-98382 bpf: Reject dev-bound-only programs on other devices
CVE-2026-98381 veth: manage XDP program pointers during channel resize
CVE-2026-98380 net/sched: reject IDR error pointers when deleting actions
CVE-2026-98378 bpf: Skip unsettled links in link iterator
CVE-2026-98379 netfilter: ip6t_rpfilter: reject routes without inet6_dev
CVE-2026-98377 vlan: require the MAC header to be present in __vlan_insert_inner_tag()
CVE-2026-98376 bpf: Use array_map_meta_equal for percpu array inner map replacement

IV. Related Vulnerabilities

V. Comments for CVE-2026-98375

No comments yet


Leave a comment