GHSA-52CR-C2C7-9X84

Vulnerability from github – Published: 2026-10-06 09:31 – Updated: 2026-10-06 09:31
VLAI
Details

In the Linux kernel, the following vulnerability has been resolved:

neighbour: Enforce min/max to NDTPA_INTERVAL_PROBE_TIME_MS.

NDTPA_INTERVAL_PROBE_TIME_MS sets .type and .min but misses .validation_type, so no validation is applied:

# ynl --family rt-neigh --do setneightbl \ --json '{"name": "arp_cache", "parms": {"interval-probe-time-ms": 0}}'

# ynl --family rt-neigh --dump getneightbl --output-json | \ jq '.[] | select(.name == "arp_cache" and has("config")) | .parms["interval-probe-time-ms"]' 0

Moreover, nla_get_msecs() uses msecs_to_jiffies(), and u64 is silently cast to u32, so a larger value can bypass the min check:

e.g. 4294967296 == 0x100000000

# ynl --family rt-neigh --do setneightbl \ --json '{"name": "arp_cache", "parms": {"interval-probe-time-ms": 4294967296}}'

# ynl --family rt-neigh --dump getneightbl --output-json | \ jq '.[] | select(.name == "arp_cache" and has("config")) | .parms["interval-probe-time-ms"]' 0

msecs_to_jiffies() returns MAX_JIFFY_OFFSET if the value is larger than INT_MAX. Also, INT_MAX ms overflows int NEIGH_VAR() when HZ > 1000 (Alpha, MIPS), and passing a negative integer to queue_delayed_work(unsigned long delay) causes sign extension, which wraps around the expiry time to the past, resulting in it being handled as 0 delay in the timer wheel.

Let's use NLA_POLICY_FULL_RANGE() and limit the max to 1 day.

The same max check is applied to sysctl as well.

Note that this controls the probe interval for NTF_MANAGED entries, so the max of 1 day is unlikely to break any deployments.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2026-98317"
  ],
  "database_specific": {
    "cwe_ids": [],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2026-10-06T09:18:23Z",
    "severity": null
  },
  "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nneighbour: Enforce min/max to NDTPA_INTERVAL_PROBE_TIME_MS.\n\nNDTPA_INTERVAL_PROBE_TIME_MS sets .type and .min but misses\n.validation_type, so no validation is applied:\n\n  # ynl --family rt-neigh --do setneightbl \\\n  --json \u0027{\"name\": \"arp_cache\", \"parms\": {\"interval-probe-time-ms\": 0}}\u0027\n\n  # ynl --family rt-neigh --dump getneightbl --output-json | \\\n  jq \u0027.[] | select(.name == \"arp_cache\" and has(\"config\"))\n          | .parms[\"interval-probe-time-ms\"]\u0027\n  0\n\nMoreover, nla_get_msecs() uses msecs_to_jiffies(), and u64 is\nsilently cast to u32, so a larger value can bypass the min check:\n\n  e.g. 4294967296 == 0x100000000\n\n  # ynl --family rt-neigh --do setneightbl \\\n  --json \u0027{\"name\": \"arp_cache\", \"parms\": {\"interval-probe-time-ms\": 4294967296}}\u0027\n\n  # ynl --family rt-neigh --dump getneightbl --output-json | \\\n  jq \u0027.[] | select(.name == \"arp_cache\" and has(\"config\"))\n          | .parms[\"interval-probe-time-ms\"]\u0027\n  0\n\nmsecs_to_jiffies() returns MAX_JIFFY_OFFSET if the value is\nlarger than INT_MAX.  Also, INT_MAX ms overflows int NEIGH_VAR()\nwhen HZ \u003e 1000 (Alpha, MIPS), and passing a negative integer to\nqueue_delayed_work(unsigned long delay) causes sign extension,\nwhich wraps around the expiry time to the past, resulting in it\nbeing handled as 0 delay in the timer wheel.\n\nLet\u0027s use NLA_POLICY_FULL_RANGE() and limit the max to 1 day.\n\nThe same max check is applied to sysctl as well.\n\nNote that this controls the probe interval for NTF_MANAGED\nentries, so the max of 1 day is unlikely to break any\ndeployments.",
  "id": "GHSA-52cr-c2c7-9x84",
  "modified": "2026-10-06T09:31:34Z",
  "published": "2026-10-06T09:31:34Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-98317"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/6d79b223ec44ada58ad37db42f539b60985a7722"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/8550b50e49b01b572e653e572f24ddd73949aa74"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/982c7f66c04134b77126edbfd8a63ecd6928cfd9"
    }
  ],
  "schema_version": "1.4.0",
  "severity": []
}



Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Forecast uses a logistic model when the trend is rising, or an exponential decay model when the trend is falling. Fitted via linearized least squares.

Sightings

Author Source Type Date Other

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or observed by the user.
  • Confirmed: The vulnerability has been validated from an analyst's perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
  • Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
  • Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
  • Not confirmed: The user expressed doubt about the validity of the vulnerability.
  • Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.

Loading…

Loading…

Loading…

Related by attack behaviour

Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.


Loading…