HIGH Introduced in 3.16
net GSO Header Panic
CVE-2026-53091
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:H
KernelScan AI8.2HIGH
01Description
In the Linux kernel, the following vulnerability has been resolved: net: pull headers in qdisc_pkt_len_segs_init() Most ndo_start_xmit() methods expects headers of gso packets to be already in skb->head. net/core/tso.c users are particularly at risk, because tso_build_hdr() does a memcpy(hdr, skb->data, hdr_len); qdisc_pkt_len_segs_init() already does a dissection of gso packets. Use pskb_may_pull() instead of skb_header_pointer() to make sure drivers do not have to reimplement this. Some malicious packets could be fed, detect them so that we can drop them sooner with a new SKB_DROP_REASON_SKB_BAD_GSO drop_reason.
02KernelScan AI Analysis
Risk summary
A remote attacker can send a maliciously crafted GSO (Generic Segmentation Offload) packet with invalid or missing transport headers, causing the kernel to access memory incorrectly in network drivers that use the TSO helper API. The out-of-bounds read can leak slab data into transmitted packet headers (Confidentiality:Low) and will eventually hit unmapped pages or trigger an invalid memcpy, resulting in a kernel panic or denial of service (Availability:High). The vulnerability is reachable without authentication from the network, affecting any system that processes GSO packets through the qdisc layer, including routers, bridges, VPN endpoints, and multi-tenant container or VM hosts.
Vulnerability analysis
The root cause is in qdisc_pkt_len_segs_init() in net/core/dev.c, which used skb_header_pointer() to access TCP/UDP headers in GSO packets. skb_header_pointer() can return a pointer to a temporary buffer or to paged data without pulling the data into the linear skb->head region. Most ndo_start_xmit() implementations and the tso_build_hdr() function in net/core/tso.c assume that GSO packet headers are already in skb->head (linear area), performing direct memcpy() from skb->data. When a malicious or malformed GSO packet is fed with headers not in the linear area, or with invalid header lengths (e.g., TCP header length field indicating less than sizeof(struct tcphdr)), drivers read from wrong memory locations. This constitutes an out-of-bounds read (CWE-125): the memcpy copies attacker-controlled lengths from an invalid source, leaking slab contents into outgoing segment headers (C:Low) and causing a kernel crash when unmapped memory is touched (A:High). The fix replaces skb_header_pointer() with pskb_may_pull(), which ensures headers are pulled into the linear skb->head region before any driver accesses them. Additionally, the fix adds validation for malformed GSO packets (invalid TCP header length, zero or negative payload) and introduces a new SKB_DROP_REASON_SKB_BAD_GSO drop reason, causing such packets to be dropped early in __dev_queue_xmit() before reaching any driver. The attack surface is the network stack transmit path: any packet that reaches the qdisc layer with GSO metadata set—whether from local sockets, forwarded traffic, bridge/router paths, or virtual interfaces—can trigger this path. No privileges are required for a remote attacker to send such packets to a forwarding system.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| 7.0 | 3.16 | 7.0.10 | 9d4f5c68f5ad |
| mainline | 3.16 | 7.1 | 7fb4c1967011 |