In the Linux kernel, the following vulnerability has been resolved:
veth: Ensure eth header is in skb's linear part
After feeding a decapsulated packet to a veth device with act_mirred, skb_headlen() may be 0. But veth_xmit() calls __dev_forward_skb(), which expects at least ETH_HLEN byte of linear data (as __dev_forward_skb2() calls eth_type_trans(), which pulls ETH_HLEN bytes unconditionally).
Use pskb_may_pull() to ensure veth_xmit() respects this constraint.
kernel BUG at include/linux/skbuff.h:2328! RIP: 0010:eth_type_trans+0xcf/0x140 Call Trace: <IRQ> __dev_forward_skb2+0xe3/0x160 veth_xmit+0x6e/0x250 [veth] dev_hard_start_xmit+0xc7/0x200 __dev_queue_xmit+0x47f/0x520 ? skb_ensure_writable+0x85/0xa0 ? skb_mpls_pop+0x98/0x1c0 tcf_mirred_act+0x442/0x47e [act_mirred] tcf_action_exec+0x86/0x140 fl_classify+0x1d8/0x1e0 [cls_flower] ? dma_pte_clear_level+0x129/0x1a0 ? dma_pte_clear_level+0x129/0x1a0 ? prb_fill_curr_block+0x2f/0xc0 ? skb_copy_bits+0x11a/0x220 __tcf_classify+0x58/0x110 tcf_classify_ingress+0x6b/0x140 __netif_receive_skb_core.constprop.0+0x47d/0xfd0 ? __iommu_dma_unmap_swiotlb+0x44/0x90 __netif_receive_skb_one_core+0x3d/0xa0 netif_receive_skb+0x116/0x170 be_process_rx+0x22f/0x330 [be2net] be_poll+0x13c/0x370 [be2net] __napi_poll+0x2a/0x170 net_rx_action+0x22f/0x2f0 __do_softirq+0xca/0x2a8 __irq_exit_rcu+0xc1/0xe0 common_interrupt+0x83/0xa0
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade kernel-livepatch-5.10.112-108.499Upgrade bpftoolUpgrade kernel-develUpgrade kernel-tools-develUpgrade kernel-livepatch-4.14.276-211.499Upgrade kernel-tools-debuginfoUpgrade perfUpgrade kernel-debuginfo-common-aarch64Upgrade perf-debuginfoUpgrade kernel-debuginfoUpgrade python-perfUpgrade kernel-headersUpgrade python-perf-debuginfoUpgrade bpftool-debuginfoUpgrade kernel-toolsUpgrade kernel-debuginfo-common-x86_64Upgrade kernel | May 21, 2025 | Feb 26, 2025 |
| Debian | — | Upgrade linux | Feb 27, 2025 | Feb 27, 2025 |
| Huawei Euleros 2_0_sp13 | — | Upgrade kernelUpgrade python3-perfUpgrade kernel-abi-stablelistsUpgrade kernel-tools-libsUpgrade kernel-toolsUpgrade bpftool | Jul 1, 2025 | Feb 26, 2025 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Feb 26, 2025 |
| Ubuntu | — | Upgrade linux-gcp-4.15Upgrade linux-realtimeUpgrade linux-ibmUpgrade linux-azure-5.4Upgrade linux-gcp-5.4Upgrade linux-fipsUpgrade linux-azureUpgrade linux-azure-4.15Upgrade linux-hwe-5.15Upgrade linux-intel-iotg-5.15Upgrade linux-lowlatencyUpgrade linux-azure-5.15Upgrade linux-aws-hweUpgrade linux-gcp-fipsUpgrade linux-intel-iotgUpgrade linux-hweUpgrade linux-hwe-5.4Upgrade linux-iotUpgrade linux-aws-fipsUpgrade linux-azure-fipsUpgrade linux-kvmUpgrade linux-oracleUpgrade linux-oracle-5.4Upgrade linux-ibm-5.4Upgrade linux-raspi-5.4Upgrade linux-raspiUpgrade linux-gcpUpgrade linuxUpgrade linux-awsUpgrade linux-lowlatency-hwe-5.15Upgrade linux-aws-5.4Upgrade linux-bluefieldUpgrade linux-gke | Mar 3, 2025 | Feb 26, 2025 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | May 27, 2026 | Feb 26, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub