天下漏洞,尽知其名
MEDIUM

CVE-2026-98375 Linux 内核 xen/netfront 短以太网头处理漏洞

影响可导致内核 BUG 崩溃或越界读取,造成拒绝服务

MEDIUM
暂无 CVSS 评分
AI 研判

Linux 内核 xen/netfront 驱动在 handle_incoming_queue() 中按后端提供的首槽长度拉取数据,未校验是否达到以太网头长度 ETH_HLEN。当首槽短于 ETH_HLEN 且后续仍有数据槽时,skb 头部短于以太网头而 skb->len 更长,eth_type_trans() 会在 __skb_pull() 中触发 BUG();若整包短于 ETH_HLEN,则会越界读取数据。

影响范围

Linux 内核 xen/netfront

受影响组件为 Linux 内核 xen/netfront 驱动,具体受影响版本范围暂无公开信息,建议以官方补丁说明为准。

漏洞详情

漏洞类型为输入校验缺失导致的拒绝服务/越界读取。成因是 pull_to 取自 Xen 后端且被限制在 RX_COPY_THRESHOLD,但未与 ETH_HLEN 比较,且 pull 返回值被忽略。利用方式是恶意或异常的后端发送首槽过短的 RX 数据包,触发内核 BUG 或越界读取。

利用条件与风险

利用前提是攻击者能控制或影响 Xen 网络后端行为(如恶意后端或异常流量)。实战中可造成客户机内核崩溃,形成拒绝服务。

修复建议

官方修复方案为在拉取时至少拉取 ETH_HLEN,失败则丢弃该数据包,并检查 pull 的返回值。临时缓解措施暂无公开信息,建议及时更新内核补丁。

原始情报

In the Linux kernel, the following vulnerability has been resolved:

xen/netfront: drop RX packets with a short Ethernet header

handle_incoming_queue() pulls pull_to bytes into the head before
calling eth_type_trans(). pull_to is the length of the first RX slot,
capped at RX_COPY_THRESHOLD, and that length comes from the backend.
Nothing checks it against ETH_HLEN.

If the first slot is shorter than ETH_HLEN and more slots follow, the
head ends up shorter than an Ethernet header while skb->len is longer,
and eth_type_trans() BUG()s in __skb_pull(). If the whole packet is
shorter than ETH_HLEN, eth_type_trans() reads the header past the end
of the data instead.

Pull at least ETH_HLEN, and drop the packet if that fails, which also
drops packets too short to hold an Ethernet header. This also checks
the return value of the pull, which was ignored.