lwt_bpf: Restore reserved headroom after xmit program

Summary

CVECVE-2026-90160
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-09-17 17:17:09 UTC
Updated2026-09-17 17:17:09 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: lwt_bpf: Restore reserved headroom after xmit program ip_finish_output2() expands an skb to LL_RESERVED_SPACE(dev) before LWT xmit. An LWT_XMIT BPF program can then modify the skb head and still return BPF_OK, so bpf_xmit() rechecks the remaining headroom before the skb continues to neighbour output. That recheck uses dst->dev->hard_header_len. This is not enough for the neighbour cached-header path: neigh_hh_output() copies the cached hardware header using the aligned hh_cache size, HH_DATA_MOD for short headers or HH_DATA_ALIGN(hh_len) otherwise. On Ethernet, hard_header_len is 14 but the cached copy needs 16 bytes. If an LWT_XMIT BPF program calls bpf_skb_change_head(skb, 1, 0), the skb can still have 15 bytes of headroom after the program. The existing check accepts that, after which neigh_hh_output() hits its headroom warning and drops the skb. Use LL_RESERVED_SPACE(dst->dev) in the post-BPF headroom check to match the reservation made before LWT xmit.

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected 3a0af8fd61f90920f6fa04e4f1e9a6a73c1b4fd2 753e5cdcca5474d230d62bb3489e5168ab27c272 git Not specified
CNA Linux Linux affected 3a0af8fd61f90920f6fa04e4f1e9a6a73c1b4fd2 c488071c3441fa34f5a87cd6c12ce2cc6304f20e git Not specified
CNA Linux Linux affected 3a0af8fd61f90920f6fa04e4f1e9a6a73c1b4fd2 a38c0eb447e2dd0120a2ebcdba470f9505ac8907 git Not specified
CNA Linux Linux affected 3a0af8fd61f90920f6fa04e4f1e9a6a73c1b4fd2 de2b2004e16f2930eb689175e2c1998b0a68d499 git Not specified
CNA Linux Linux affected 3a0af8fd61f90920f6fa04e4f1e9a6a73c1b4fd2 7d043e24520a273c362be5dd7d9c82796879a49b git Not specified
CNA Linux Linux affected 3a0af8fd61f90920f6fa04e4f1e9a6a73c1b4fd2 7cf561843ed0ad57501892a65abb77957e6c800f git Not specified
CNA Linux Linux affected 3a0af8fd61f90920f6fa04e4f1e9a6a73c1b4fd2 179a5b2171573d94a25c9aa8e1c9f9ac352ad316 git Not specified
CNA Linux Linux affected 3a0af8fd61f90920f6fa04e4f1e9a6a73c1b4fd2 5fe7007aed9ad069b2bd77e5d0c875c64f5c0269 git Not specified
CNA Linux Linux affected 4.10 Not specified
CNA Linux Linux unaffected 4.10 semver Not specified
CNA Linux Linux unaffected 5.10.270 5.10.* semver Not specified
CNA Linux Linux unaffected 5.15.221 5.15.* semver Not specified
CNA Linux Linux unaffected 6.1.188 6.1.* semver Not specified
CNA Linux Linux unaffected 6.6.157 6.6.* semver Not specified
CNA Linux Linux unaffected 6.12.110 6.12.* semver Not specified
CNA Linux Linux unaffected 6.18.52 6.18.* semver Not specified
CNA Linux Linux unaffected 7.2.6 7.2.* semver Not specified
CNA Linux Linux unaffected 7.3-rc1 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/a38c0eb447e2dd0120a2ebcdba470f9505ac8907 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/7cf561843ed0ad57501892a65abb77957e6c800f 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/753e5cdcca5474d230d62bb3489e5168ab27c272 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/de2b2004e16f2930eb689175e2c1998b0a68d499 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/7d043e24520a273c362be5dd7d9c82796879a49b 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/5fe7007aed9ad069b2bd77e5d0c875c64f5c0269 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/c488071c3441fa34f5a87cd6c12ce2cc6304f20e 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/179a5b2171573d94a25c9aa8e1c9f9ac352ad316 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report