HIGH Introduced in 6.14
xfrm RuntReassembly OOB
CVE-2026-98371
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
01Description
In the Linux kernel, the following vulnerability has been resolved: xfrm: iptfs: fix runt reassembly panic from short inner tot_len When the start of an inner packet is split across two outer packets such that fewer than 4 bytes land at the end of the first one, __input_process_payload() saves those bytes as a runt and skips the iplen/iphlen validation performed for in-place packets. When the continuation packet arrives, iptfs_reassem_cont() only requires the declared inner length to be >= sizeof(ra_runt) (6) before allocating the reassembly skb with that attacker-controlled length. However, __iptfs_iphlen() always returns the fixed minimum IP header size (20 for IPv4, 40 for IPv6), so for an inner IPv4 tot_len in [6, 19] the header-completion copy writes past the declared packet length, and the subsequent "ipremain -= copylen" underflows to ~4GB, leaving the payload copy length bounded only by blkoff (up to 64KB). At runtime the skb_put() tailroom check turns this into skb_over_panic(), i.e. an unprivileged kernel panic (DoS), reachable locally via userns+netns IPTFS SAs and remotely against IPTFS VPN gateways when the decrypted outer skb is linear (e.g. AF_PACKET taps, tun/tap delivery). Align the runt path with the normal path by requiring the declared inner length to cover at least the IP header size. This also subsumes the previous >= sizeof(ra_runt) check, since the minimum IP header is always larger than the runt buffer. This issue was found by the autokbug dynamic kernel fuzzer at Tencent Yunding Lab.
02KernelScan AI Analysis
Risk summary
An unprivileged local user can trigger a kernel panic via crafted IPTFS packets through user namespace IPTFS security associations. The bug is also reachable remotely against IPTFS VPN gateways by a peer sending malformed encapsulated packets, causing denial of service.
Vulnerability analysis
When the start of an inner packet is split across two outer IPTFS packets with fewer than 4 bytes in the first fragment, the reassembly code saves a partial header (runt) but skips the length validation that normal packets receive. On the continuation packet, the code only checks that the declared inner length is at least the runt buffer size (6 bytes) rather than the full IP header size (20 bytes for IPv4, 40 for IPv6). With a crafted inner length between 6 and 19 bytes, the header-completion copy writes past the allocated buffer, an internal length counter underflows to roughly 4 GB, and the subsequent oversized payload copy triggers a kernel panic. The fix aligns the runt path with the normal path by requiring the declared inner length to cover at least the IP header size. The vulnerability is reachable locally by unprivileged users through user namespaces with IPTFS security associations, and remotely against IPTFS VPN gateways by a peer sending crafted encapsulated packets when the decrypted outer skb is linear.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| 6.18 | 6.14 | 6.18.54 | a7018ee0ea86 |
| 7.2 | 6.14 | 7.2.8 | 5b8afb56ccb7 |
| mainline | 6.14 | 7.3-rc4 | dc33262be1fe |