<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 09 Oct 2026 01:16:18 +0000</lastBuildDate>
    <item>
      <title>CVE-2024-26635 — llc: Drop support for ETH_P_TR_802_2.</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2024-26635</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;llc: Drop support for ETH_P_TR_802_2.&lt;/p&gt;
&lt;p&gt;syzbot reported an uninit-value bug below. [0]&lt;/p&gt;
&lt;p&gt;llc supports ETH_P_802_2 (0x0004) and used to support ETH_P_TR_802_2
(0x0011), and syzbot abused the latter to trigger the bug.&lt;/p&gt;
&lt;p&gt;write$tun(r0, &amp;amp;(0x7f0000000040)={@val={0x0, 0x11}, @val, @mpls={[], @llc={@snap={0xaa, 0x1, &amp;#39;)&amp;#39;, &amp;#34;90e5dd&amp;#34;}}}}, 0x16)&lt;/p&gt;
&lt;p&gt;llc_conn_handler() initialises local variables {saddr,daddr}.mac
based on skb in llc_pdu_decode_sa()/llc_pdu_decode_da() and passes
them to __llc_lookup().&lt;/p&gt;
&lt;p&gt;However, the initialisation is done only when skb-&amp;gt;protocol is
htons(ETH_P_802_2), otherwise, __llc_lookup_established() and
__llc_lookup_listener() will read garbage.&lt;/p&gt;
&lt;p&gt;The missing initialisation existed prior to commit 211ed865108e
(&amp;#34;net: delete all instances of special processing for token ring&amp;#34;).&lt;/p&gt;
&lt;p&gt;It removed the part to kick out the token ring stuff but forgot to
close the door allowing ETH_P_TR_802_2 packets to sneak into llc_rcv().&lt;/p&gt;
&lt;p&gt;Let&amp;#39;s remove llc_tr_packet_type and complete the deprecation.&lt;/p&gt;
&lt;p&gt;[0]:
BUG: KMSAN: uninit-value in __llc_lookup_established+0xe9d/0xf90
 __llc_lookup_established+0xe9d/0xf90
 __llc_lookup net/llc/llc_conn.c:611 [inline]
 llc_conn_handler+0x4bd/0x1360 net/llc/llc_conn.c:791
 llc_rcv+0xfbb/0x14a0 net/llc/llc_input.c:206
 __netif_receive_skb_one_core net/core/dev.c:5527 [inline]
 __netif_receive_skb+0x1a6/0x5a0 net/core/dev.c:5641
 netif_receive_skb_internal net/core/dev.c:5727 [inline]
 netif_re…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;llc: Drop support for ETH_P_TR_802_2.&lt;/p&gt;
&lt;p&gt;syzbot reported an uninit-value bug below. [0]&lt;/p&gt;
&lt;p&gt;llc supports ETH_P_802_2 (0x0004) and used to support ETH_P_TR_802_2
(0x0011), and syzbot abused the latter to trigger the bug.&lt;/p&gt;
&lt;p&gt;write$tun(r0, &amp;amp;(0x7f0000000040)={@val={0x0, 0x11}, @val, @mpls={[], @llc={@snap={0xaa, 0x1, &amp;#39;)&amp;#39;, &amp;#34;90e5dd&amp;#34;}}}}, 0x16)&lt;/p&gt;
&lt;p&gt;llc_conn_handler() initialises local variables {saddr,daddr}.mac
based on skb in llc_pdu_decode_sa()/llc_pdu_decode_da() and passes
them to __llc_lookup().&lt;/p&gt;
&lt;p&gt;However, the initialisation is done only when skb-&amp;gt;protocol is
htons(ETH_P_802_2), otherwise, __llc_lookup_established() and
__llc_lookup_listener() will read garbage.&lt;/p&gt;
&lt;p&gt;The missing initialisation existed prior to commit 211ed865108e
(&amp;#34;net: delete all instances of special processing for token ring&amp;#34;).&lt;/p&gt;
&lt;p&gt;It removed the part to kick out the token ring stuff but forgot to
close the door allowing ETH_P_TR_802_2 packets to sneak into llc_rcv().&lt;/p&gt;
&lt;p&gt;Let&amp;#39;s remove llc_tr_packet_type and complete the deprecation.&lt;/p&gt;
&lt;p&gt;[0]:
BUG: KMSAN: uninit-value in __llc_lookup_established+0xe9d/0xf90
 __llc_lookup_established+0xe9d/0xf90
 __llc_lookup net/llc/llc_conn.c:611 [inline]
 llc_conn_handler+0x4bd/0x1360 net/llc/llc_conn.c:791
 llc_rcv+0xfbb/0x14a0 net/llc/llc_input.c:206
 __netif_receive_skb_one_core net/core/dev.c:5527 [inline]
 __netif_receive_skb+0x1a6/0x5a0 net/core/dev.c:5641
 netif_receive_skb_internal net/core/dev.c:5727 [inline]
 netif_re…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2024-26635</guid>
    </item>
  </channel>
</rss>
