<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 00:34:24 +0000</lastBuildDate>
    <item>
      <title>CVE-2024-36933 — nsh: Restore skb-&gt;{protocol,data,mac_header} for outer header in nsh_gso_segment().</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2024-36933</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;nsh: Restore skb-&amp;gt;{protocol,data,mac_header} for outer header in nsh_gso_segment().&lt;/p&gt;
&lt;p&gt;syzbot triggered various splats (see [0] and links) by a crafted GSO
packet of VIRTIO_NET_HDR_GSO_UDP layering the following protocols:&lt;/p&gt;
&lt;p&gt;ETH_P_8021AD + ETH_P_NSH + ETH_P_IPV6 + IPPROTO_UDP&lt;/p&gt;
&lt;p&gt;NSH can encapsulate IPv4, IPv6, Ethernet, NSH, and MPLS.  As the inner
protocol can be Ethernet, NSH GSO handler, nsh_gso_segment(), calls
skb_mac_gso_segment() to invoke inner protocol GSO handlers.&lt;/p&gt;
&lt;p&gt;nsh_gso_segment() does the following for the original skb before
calling skb_mac_gso_segment()&lt;/p&gt;
&lt;p&gt;1. reset skb-&amp;gt;network_header
  2. save the original skb-&amp;gt;{mac_heaeder,mac_len} in a local variable
  3. pull the NSH header
  4. resets skb-&amp;gt;mac_header
  5. set up skb-&amp;gt;mac_len and skb-&amp;gt;protocol for the inner protocol.&lt;/p&gt;
&lt;p&gt;and does the following for the segmented skb&lt;/p&gt;
&lt;p&gt;6. set ntohs(ETH_P_NSH) to skb-&amp;gt;protocol
  7. push the NSH header
  8. restore skb-&amp;gt;mac_header
  9. set skb-&amp;gt;mac_header + mac_len to skb-&amp;gt;network_header
 10. restore skb-&amp;gt;mac_len&lt;/p&gt;
&lt;p&gt;There are two problems in 6-7 and 8-9.&lt;/p&gt;
&lt;p&gt;(a)
  After 6 &amp;amp; 7, skb-&amp;gt;data points to the NSH header, so the outer header
  (ETH_P_8021AD in this case) is stripped when skb is sent out of netdev.&lt;/p&gt;
&lt;p&gt;Also, if NSH is encapsulated by NSH + Ethernet (so NSH-Ethernet-NSH),
  skb_pull() in the first nsh_gso_segment() will make skb-&amp;gt;data point
  to the middle of the outer NSH or Ethernet header because the Ethernet…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;nsh: Restore skb-&amp;gt;{protocol,data,mac_header} for outer header in nsh_gso_segment().&lt;/p&gt;
&lt;p&gt;syzbot triggered various splats (see [0] and links) by a crafted GSO
packet of VIRTIO_NET_HDR_GSO_UDP layering the following protocols:&lt;/p&gt;
&lt;p&gt;ETH_P_8021AD + ETH_P_NSH + ETH_P_IPV6 + IPPROTO_UDP&lt;/p&gt;
&lt;p&gt;NSH can encapsulate IPv4, IPv6, Ethernet, NSH, and MPLS.  As the inner
protocol can be Ethernet, NSH GSO handler, nsh_gso_segment(), calls
skb_mac_gso_segment() to invoke inner protocol GSO handlers.&lt;/p&gt;
&lt;p&gt;nsh_gso_segment() does the following for the original skb before
calling skb_mac_gso_segment()&lt;/p&gt;
&lt;p&gt;1. reset skb-&amp;gt;network_header
  2. save the original skb-&amp;gt;{mac_heaeder,mac_len} in a local variable
  3. pull the NSH header
  4. resets skb-&amp;gt;mac_header
  5. set up skb-&amp;gt;mac_len and skb-&amp;gt;protocol for the inner protocol.&lt;/p&gt;
&lt;p&gt;and does the following for the segmented skb&lt;/p&gt;
&lt;p&gt;6. set ntohs(ETH_P_NSH) to skb-&amp;gt;protocol
  7. push the NSH header
  8. restore skb-&amp;gt;mac_header
  9. set skb-&amp;gt;mac_header + mac_len to skb-&amp;gt;network_header
 10. restore skb-&amp;gt;mac_len&lt;/p&gt;
&lt;p&gt;There are two problems in 6-7 and 8-9.&lt;/p&gt;
&lt;p&gt;(a)
  After 6 &amp;amp; 7, skb-&amp;gt;data points to the NSH header, so the outer header
  (ETH_P_8021AD in this case) is stripped when skb is sent out of netdev.&lt;/p&gt;
&lt;p&gt;Also, if NSH is encapsulated by NSH + Ethernet (so NSH-Ethernet-NSH),
  skb_pull() in the first nsh_gso_segment() will make skb-&amp;gt;data point
  to the middle of the outer NSH or Ethernet header because the Ethernet…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2024-36933</guid>
    </item>
  </channel>
</rss>
