CRITICAL Introduced in 7.0
geneve GroComplete OOB
CVE-2026-72408
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
KernelScan AI9.1CRITICAL
01Description
In the Linux kernel, the following vulnerability has been resolved: geneve: gate GRO hint in geneve_gro_complete() on gs->gro_hint geneve_gro_receive() reads the GRO hint through geneve_sk_gro_hint_off(), which honours it only when the socket enabled IFLA_GENEVE_GRO_HINT (gs->gro_hint). geneve_gro_complete() instead calls the low-level geneve_opt_gro_hint_off() and acts on the hint unconditionally. On a tunnel without the hint, receive aggregates the frames as plain ETH_P_TEB while complete still honours an attacker-supplied hint option: it inflates gh_len by gro_hint->nested_hdr_len (u8) and redirects the dispatch type, so the inner gro_complete handler runs at nhoff + gh_len, an offset receive never pulled nor validated, reading out of bounds of the skb head: BUG: KASAN: slab-out-of-bounds in ipv6_gro_complete (net/ipv6/ip6_offload.c:196) Read of size 1 at addr ffff88800fe91980 by task exploit/153 ipv6_gro_complete (net/ipv6/ip6_offload.c:196) geneve_gro_complete (drivers/net/geneve.c:965) udp_gro_complete (net/ipv4/udp_offload.c:940) inet_gro_complete (net/ipv4/af_inet.c:1621) __gro_flush (net/core/gro.c:306) Gate the complete path on gs->gro_hint too via geneve_sk_gro_hint_off(), so both paths agree. Tunnels that enable the hint are unaffected.
02KernelScan AI Analysis
Risk summary
A remote attacker who can send crafted GENEVE packets to a host with a GENEVE tunnel configured can trigger an out-of-bounds read in the kernel's GRO completion path. The read occurs at an attacker-controlled offset beyond the validated packet buffer, potentially leaking kernel memory and causing a kernel panic. No privileges on the target system are required.
Vulnerability analysis
The GENEVE tunnel driver's GRO completion path processes an attacker-supplied GRO hint option unconditionally, even when the tunnel was not configured to use GRO hints. The receive path correctly gates hint processing on the tunnel's configuration, but the completion path bypasses that check, causing the inner protocol completion handler to operate at an offset derived from the attacker-controlled hint value — reading beyond the validated bounds of the packet buffer. The fix aligns the completion path with the receive path by gating GRO hint processing on the tunnel's configured hint setting, so both paths agree on whether to honor the option. The vulnerability is reachable by any attacker who can send crafted GENEVE packets to a host with a GENEVE tunnel configured, requiring no privileges on the target system.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| 7.1 | 7.0 | 7.1.5 | 49c2e7c0a699 |
| mainline | 7.0 | 7.2-rc1 | 2651c1744458 |