CRITICAL Introduced in 7.0
geneve GroComplete OOB
CVE-2026-72407
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
KernelScan AI8.1HIGH
01Description
In the Linux kernel, the following vulnerability has been resolved: geneve: validate inner network offset in geneve_gro_complete() Even with both paths gated on gs->gro_hint, geneve_gro_complete() re-derives the inner dispatch type and length from the packet and the current gs->gro_hint, independently of geneve_gro_receive(). The two can disagree if gs->gro_hint flips under a concurrent geneve_quiesce()/ geneve_unquiesce() (sk_user_data is NULL across a synchronize_net()), or if the re-read option bytes differ from the ones receive parsed. geneve_gro_receive() already records the inner network header position in NAPI_GRO_CB()->inner_network_offset. Have geneve_gro_complete() compute the offset it is about to dispatch at, adding ETH_HLEN in the ETH_P_TEB case where eth_gro_complete() steps over the inner MAC header, and bail out if it lands past inner_network_offset. Use a lower bound rather than exact equality: between gh_len and the inner L3 header, geneve_gro_receive() may also have pulled an inner VLAN tag (vlan_gro_receive() advances the recorded offset past it), which only moves inner_network_offset further out. A valid frame therefore always satisfies inner_nh <= inner_network_offset, while a gh_len inflated by a hint gro_receive() did not honour dispatches past the validated inner header, i.e. the out-of-bounds completion. Only the latter is rejected.
02KernelScan AI Analysis
Risk summary
A host with a configured Geneve tunnel that processes GRO receive offload is vulnerable to out-of-bounds memory access when the GRO completion path disagrees with the receive path about the inner packet header position. An attacker who can send Geneve-encapsulated UDP packets to the tunnel endpoint can trigger this, potentially causing kernel memory corruption or a crash. Exploitation requires a race window or crafted option bytes that cause the disagreement.
Vulnerability analysis
The Geneve tunnel driver's GRO completion handler independently re-derives the inner packet header offset from the packet and a socket-level hint, rather than trusting the offset that the receive handler already validated and recorded. If the hint changes concurrently (for example during a tunnel quiesce/unquiesce cycle) or the re-read option bytes differ from what the receive path parsed, the completion handler can compute an inflated inner header length and dispatch at an offset past the validated inner network header position, causing out-of-bounds access on the packet buffer. The fix adds a bounds check that compares the computed dispatch offset against the inner network header position recorded during receive, returning an error if the offset exceeds the validated position. An attacker who can send Geneve-encapsulated UDP packets to a host with a configured Geneve tunnel can reach this code path; exploitation depends on the hint flipping concurrently or option bytes that cause the two paths to disagree.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| mainline | 7.0 | 7.2-rc1 | cbb0d30a1ad6 |
| 7.1 | 7.0 | 7.1.5 | e2087447f562 |