GHSA-M2P4-C77R-P2C7

Vulnerability from github – Published: 2026-10-06 09:31 – Updated: 2026-10-06 09:31
VLAI
Details

In the Linux kernel, the following vulnerability has been resolved:

pppoatm: ensure a writable skb header and linear data

In pppoatm_send(), LLC encapsulation checks whether there is sufficient headroom for the 4-byte LLC header, but does not ensure that the skb header is writable.

Normal transmit packets passing through ppp_start_xmit() have their header unshared via skb_cow_head(). However, packets can also reach pppoatm_send() via PPP channel bridging (PPPIOCBRIDGECHAN) without going through ppp_start_xmit().

Use skb_cow_head() to ensure both sufficient headroom and a writable header before pushing the LLC header.

While at it: - Call pskb_may_pull(skb, 1) before inspecting skb->data[0] to prevent out-of-bounds reads on zero-length or non-linear frames (e.g. from bridging). - Defer SC_COMP_PROT protocol compression until after pppoatm_may_send() succeeds. This eliminates the temporary skb allocation on admission failure and completely removes the fragile "undo" heuristic at the nospace label, avoiding any risk of reading uninitialized headroom or performing an unbalanced skb_push().

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2026-98287"
  ],
  "database_specific": {
    "cwe_ids": [],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2026-10-06T09:18:18Z",
    "severity": null
  },
  "details": "In the Linux kernel, the following vulnerability has been resolved:\n\npppoatm: ensure a writable skb header and linear data\n\nIn pppoatm_send(), LLC encapsulation checks whether there is sufficient\nheadroom for the 4-byte LLC header, but does not ensure that the skb header\nis writable.\n\nNormal transmit packets passing through ppp_start_xmit() have their header\nunshared via skb_cow_head(). However, packets can also reach pppoatm_send()\nvia PPP channel bridging (PPPIOCBRIDGECHAN) without going through\nppp_start_xmit().\n\nUse skb_cow_head() to ensure both sufficient headroom and a writable\nheader before pushing the LLC header.\n\nWhile at it:\n- Call pskb_may_pull(skb, 1) before inspecting skb-\u003edata[0] to prevent\n  out-of-bounds reads on zero-length or non-linear frames (e.g. from\n  bridging).\n- Defer SC_COMP_PROT protocol compression until after pppoatm_may_send()\n  succeeds. This eliminates the temporary skb allocation on admission failure\n  and completely removes the fragile \"undo\" heuristic at the nospace label,\n  avoiding any risk of reading uninitialized headroom or performing an\n  unbalanced skb_push().",
  "id": "GHSA-m2p4-c77r-p2c7",
  "modified": "2026-10-06T09:31:33Z",
  "published": "2026-10-06T09:31:33Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-98287"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/208ccc4d08b1897451e9ba01c016bf93ff107966"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/30992fe39e65589ed8e000425e088fa74994b811"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/8e66c5969acd859ba72fb0a7fa895623fc1b3769"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/e2f5529b0016db7d34f411408607f5cf395a542e"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/e6cd1bba7d113c15c00ac63671213a096fe4d686"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/ecc7253683a3c55caa868ce0ee530fcb0044bd3c"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/ffc448eb54f5ba80d4212c1e870cdb92b0f709fa"
    }
  ],
  "schema_version": "1.4.0",
  "severity": []
}



Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Forecast uses a logistic model when the trend is rising, or an exponential decay model when the trend is falling. Fitted via linearized least squares.

Sightings

Author Source Type Date Other

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or observed by the user.
  • Confirmed: The vulnerability has been validated from an analyst's perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
  • Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
  • Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
  • Not confirmed: The user expressed doubt about the validity of the vulnerability.
  • Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.

Loading…

Loading…

Loading…

Related by attack behaviour

Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.


Loading…