In the Linux kernel, the following vulnerability has been resolved:
veth: Ensure eth header is in skb's linear part
After feeding a decapsulated packet to a veth device with act_mirred, skb_headlen() may be 0. But veth_xmit() calls __dev_forward_skb(), which expects at least ETH_HLEN byte of linear data (as __dev_forward_skb2() calls eth_type_trans(), which pulls ETH_HLEN bytes unconditionally).
Use pskb_may_pull() to ensure veth_xmit() respects this constraint.
kernel BUG at include/linux/skbuff.h:2328! RIP: 0010:eth_type_trans+0xcf/0x140 Call Trace: <IRQ> __dev_forward_skb2+0xe3/0x160 veth_xmit+0x6e/0x250 [veth] dev_hard_start_xmit+0xc7/0x200 __dev_queue_xmit+0x47f/0x520 ? skb_ensure_writable+0x85/0xa0 ? skb_mpls_pop+0x98/0x1c0 tcf_mirred_act+0x442/0x47e [act_mirred] tcf_action_exec+0x86/0x140 fl_classify+0x1d8/0x1e0 [cls_flower] ? dma_pte_clear_level+0x129/0x1a0 ? dma_pte_clear_level+0x129/0x1a0 ? prb_fill_curr_block+0x2f/0xc0 ? skb_copy_bits+0x11a/0x220 __tcf_classify+0x58/0x110 tcf_classify_ingress+0x6b/0x140 __netif_receive_skb_core.constprop.0+0x47d/0xfd0 ? __iommu_dma_unmap_swiotlb+0x44/0x90 __netif_receive_skb_one_core+0x3d/0xa0 netif_receive_skb+0x116/0x170 be_process_rx+0x22f/0x330 [be2net] be_poll+0x13c/0x370 [be2net] __napi_poll+0x2a/0x170 net_rx_action+0x22f/0x2f0 __do_softirq+0xca/0x2a8 __irq_exit_rcu+0xc1/0xe0 common_interrupt+0x83/0xa0
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade kernelUpgrade python-perfUpgrade bpftool-debuginfoUpgrade kernel-toolsUpgrade kernel-debuginfo-common-x86_64Upgrade python-perf-debuginfoUpgrade kernel-headersUpgrade kernel-tools-debuginfoUpgrade kernel-livepatch-4.14.276-211.499Upgrade kernel-debuginfoUpgrade kernel-tools-develUpgrade perfUpgrade bpftoolUpgrade kernel-debuginfo-common-aarch64Upgrade kernel-develUpgrade kernel-livepatch-5.10.112-108.499Upgrade perf-debuginfo | May 21, 2025 | Feb 26, 2025 |
| Debian | — | Upgrade linux | Feb 27, 2025 | Feb 27, 2025 |
| Huawei Euleros 2_0_sp13 | — | Upgrade python3-perfUpgrade kernelUpgrade kernel-toolsUpgrade kernel-tools-libsUpgrade bpftoolUpgrade kernel-abi-stablelists | Jul 1, 2025 | Feb 26, 2025 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Feb 26, 2025 |
| Ubuntu | — | Upgrade linux-azureUpgrade linux-oracleUpgrade linux-ibmUpgrade linux-kvmUpgrade linux-hweUpgrade linux-gcp-5.4Upgrade linux-iotUpgrade linux-intel-iotgUpgrade linux-fipsUpgrade linux-gcp-4.15Upgrade linux-azure-4.15Upgrade linux-azure-5.4Upgrade linux-hwe-5.4Upgrade linux-azure-fipsUpgrade linux-realtimeUpgrade linux-aws-hweUpgrade linux-gcp-fipsUpgrade linux-intel-iotg-5.15Upgrade linux-lowlatencyUpgrade linux-azure-5.15Upgrade linux-hwe-5.15Upgrade linux-aws-fipsUpgrade linux-ibm-5.4Upgrade linux-awsUpgrade linux-oracle-5.4Upgrade linux-lowlatency-hwe-5.15Upgrade linuxUpgrade linux-gcpUpgrade linux-raspiUpgrade linux-raspi-5.4Upgrade linux-gkeUpgrade linux-bluefieldUpgrade linux-aws-5.4 | Mar 3, 2025 | Feb 26, 2025 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | May 27, 2026 | Feb 26, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub