GHSA-M2P4-C77R-P2C7
Vulnerability from github – Published: 2026-10-06 09:31 – Updated: 2026-10-06 09:31In the Linux kernel, the following vulnerability has been resolved:
pppoatm: ensure a writable skb header and linear data
In pppoatm_send(), LLC encapsulation checks whether there is sufficient headroom for the 4-byte LLC header, but does not ensure that the skb header is writable.
Normal transmit packets passing through ppp_start_xmit() have their header unshared via skb_cow_head(). However, packets can also reach pppoatm_send() via PPP channel bridging (PPPIOCBRIDGECHAN) without going through ppp_start_xmit().
Use skb_cow_head() to ensure both sufficient headroom and a writable header before pushing the LLC header.
While at it: - Call pskb_may_pull(skb, 1) before inspecting skb->data[0] to prevent out-of-bounds reads on zero-length or non-linear frames (e.g. from bridging). - Defer SC_COMP_PROT protocol compression until after pppoatm_may_send() succeeds. This eliminates the temporary skb allocation on admission failure and completely removes the fragile "undo" heuristic at the nospace label, avoiding any risk of reading uninitialized headroom or performing an unbalanced skb_push().
{
"affected": [],
"aliases": [
"CVE-2026-98287"
],
"database_specific": {
"cwe_ids": [],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2026-10-06T09:18:18Z",
"severity": null
},
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\npppoatm: ensure a writable skb header and linear data\n\nIn pppoatm_send(), LLC encapsulation checks whether there is sufficient\nheadroom for the 4-byte LLC header, but does not ensure that the skb header\nis writable.\n\nNormal transmit packets passing through ppp_start_xmit() have their header\nunshared via skb_cow_head(). However, packets can also reach pppoatm_send()\nvia PPP channel bridging (PPPIOCBRIDGECHAN) without going through\nppp_start_xmit().\n\nUse skb_cow_head() to ensure both sufficient headroom and a writable\nheader before pushing the LLC header.\n\nWhile at it:\n- Call pskb_may_pull(skb, 1) before inspecting skb-\u003edata[0] to prevent\n out-of-bounds reads on zero-length or non-linear frames (e.g. from\n bridging).\n- Defer SC_COMP_PROT protocol compression until after pppoatm_may_send()\n succeeds. This eliminates the temporary skb allocation on admission failure\n and completely removes the fragile \"undo\" heuristic at the nospace label,\n avoiding any risk of reading uninitialized headroom or performing an\n unbalanced skb_push().",
"id": "GHSA-m2p4-c77r-p2c7",
"modified": "2026-10-06T09:31:33Z",
"published": "2026-10-06T09:31:33Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-98287"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/208ccc4d08b1897451e9ba01c016bf93ff107966"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/30992fe39e65589ed8e000425e088fa74994b811"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/8e66c5969acd859ba72fb0a7fa895623fc1b3769"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/e2f5529b0016db7d34f411408607f5cf395a542e"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/e6cd1bba7d113c15c00ac63671213a096fe4d686"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/ecc7253683a3c55caa868ce0ee530fcb0044bd3c"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/ffc448eb54f5ba80d4212c1e870cdb92b0f709fa"
}
],
"schema_version": "1.4.0",
"severity": []
}
Sightings
| Author | Source | Type | Date | Other |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or observed by the user.
- Confirmed: The vulnerability has been validated from an analyst's perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
- Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
- Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
- Not confirmed: The user expressed doubt about the validity of the vulnerability.
- Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.
The approach is described in our paper Mapping CVEs to MITRE ATT&CK Techniques: A Curated Gold-Set Classifier and the Limits of LLM-Assisted Label Expansion.
Browse all ATT&CK techniques and the vulnerabilities related to each.
Related by attack behaviour
Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.