๐Ÿ” CVE Alert

CVE-2026-90160

UNKNOWN 0.0

lwt_bpf: Restore reserved headroom after xmit program

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: lwt_bpf: Restore reserved headroom after xmit program ip_finish_output2() expands an skb to LL_RESERVED_SPACE(dev) before LWT xmit. An LWT_XMIT BPF program can then modify the skb head and still return BPF_OK, so bpf_xmit() rechecks the remaining headroom before the skb continues to neighbour output. That recheck uses dst->dev->hard_header_len. This is not enough for the neighbour cached-header path: neigh_hh_output() copies the cached hardware header using the aligned hh_cache size, HH_DATA_MOD for short headers or HH_DATA_ALIGN(hh_len) otherwise. On Ethernet, hard_header_len is 14 but the cached copy needs 16 bytes. If an LWT_XMIT BPF program calls bpf_skb_change_head(skb, 1, 0), the skb can still have 15 bytes of headroom after the program. The existing check accepts that, after which neigh_hh_output() hits its headroom warning and drops the skb. Use LL_RESERVED_SPACE(dst->dev) in the post-BPF headroom check to match the reservation made before LWT xmit.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 17, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
3a0af8fd61f90920f6fa04e4f1e9a6a73c1b4fd2 < 753e5cdcca5474d230d62bb3489e5168ab27c272 3a0af8fd61f90920f6fa04e4f1e9a6a73c1b4fd2 < c488071c3441fa34f5a87cd6c12ce2cc6304f20e 3a0af8fd61f90920f6fa04e4f1e9a6a73c1b4fd2 < a38c0eb447e2dd0120a2ebcdba470f9505ac8907 3a0af8fd61f90920f6fa04e4f1e9a6a73c1b4fd2 < de2b2004e16f2930eb689175e2c1998b0a68d499 3a0af8fd61f90920f6fa04e4f1e9a6a73c1b4fd2 < 7d043e24520a273c362be5dd7d9c82796879a49b 3a0af8fd61f90920f6fa04e4f1e9a6a73c1b4fd2 < 7cf561843ed0ad57501892a65abb77957e6c800f 3a0af8fd61f90920f6fa04e4f1e9a6a73c1b4fd2 < 179a5b2171573d94a25c9aa8e1c9f9ac352ad316 3a0af8fd61f90920f6fa04e4f1e9a6a73c1b4fd2 < 5fe7007aed9ad069b2bd77e5d0c875c64f5c0269
Linux / Linux
4.10

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/753e5cdcca5474d230d62bb3489e5168ab27c272 git.kernel.org: https://git.kernel.org/stable/c/c488071c3441fa34f5a87cd6c12ce2cc6304f20e git.kernel.org: https://git.kernel.org/stable/c/a38c0eb447e2dd0120a2ebcdba470f9505ac8907 git.kernel.org: https://git.kernel.org/stable/c/de2b2004e16f2930eb689175e2c1998b0a68d499 git.kernel.org: https://git.kernel.org/stable/c/7d043e24520a273c362be5dd7d9c82796879a49b git.kernel.org: https://git.kernel.org/stable/c/7cf561843ed0ad57501892a65abb77957e6c800f git.kernel.org: https://git.kernel.org/stable/c/179a5b2171573d94a25c9aa8e1c9f9ac352ad316 git.kernel.org: https://git.kernel.org/stable/c/5fe7007aed9ad069b2bd77e5d0c875c64f5c0269