CVE-2026-98372: xfrm: iptfs: fix stack OOB read in iptfs_skb_reset_frag_walk()
In the Linux kernel, the following vulnerability has been resolved:
xfrm: iptfs: fix stack OOB read in iptfsskbresetfragwalk()
iptfsskbresetfragwalk() advances to the fragment containing @offset with an unbounded loop:
while (offset >= walk->past + walk->frags[walk->fragi].len) walk->past += walk->frags[walk->fragi++].len;
walk->fragi is advanced and walk->frags[walk->fragi] is dereferenced without ever checking fragi against walk->nrfrags. When the requested offset is at or beyond the total length spanned by the walk's fragments, fragi runs past nrfrags and off the end of the fixed-size on-stack frags[MAXSKBFRAGS + 1] array, reading out-of-bounds stack memory.
The two callers behave differently: iptfsskbaddfrags() already guards against this with
if (!walk->nrfrags || offset >= walk->total + walk->initialoffset) return len;
but iptfsskbcanaddfrags() has no such guard and calls iptfsskbresetfragwalk() unconditionally, so it performs the out-of-range walk. Its own "fragi < walk->nrfrags" bound check runs only afterwards, too late to prevent the read.
This is reachable from the receive path: a crafted IP-TFS (AGGFRAG) payload delivered to an IPTFS SA drives iptfsreassemcont() -> iptfsskbcanaddfrags() with an offset past the fragment total, e.g.:
BUG: KASAN: stack-out-of-bounds in iptfsskbresetfragwalk+0x235/0x250 Read of size 4 at addr ffff888008ad7210 by task repro/345 iptfsskbresetfragwalk+0x235/0x250 net/xfrm/xfrmiptfs.c:392 iptfsskbcanaddfrags+0x155/0x310 net/xfrm/xfrmiptfs.c:420 iptfsreassemcont+0xcf8/0x1140 net/xfrm/xfrmiptfs.c:902 iptfsinputordered+0x552/0x670 net/xfrm/xfrmiptfs.c:1280 iptfsinput+0x3d6/0xde0 net/xfrm/xfrmiptfs.c:1741 xfrminput+0x282f/0x6140 net/xfrm/xfrminput.c:700 xfrm4esprcv+0x93/0x120 net/ipv4/xfrm4protocol.c:104 iprcv+0x278/0x2d0 net/ipv4/ipinput.c:612
Give iptfsskbcanaddfrags() the same up-front guard that iptfsskbaddfrags() already has, so the walk is never entered with an out-of-range offset. When it triggers, the caller falls back to the existing linearize-and-copy path, which is safe.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Add the same up-front bounds guard used by iptfs_skb_add_frags() to iptfs_skb_can_add_frags(): if (!walk->nr_frags || offset >= walk->total + walk->initial_offset) return len; This prevents iptfs_skb_reset_frag_walk() from being called with an out-of-range offset.
Event History
Frequently Asked Questions
Which systems are exposed to the reachable receive-path condition?
Systems using an IPTFS security association (SA) are in scope. The issue is reachable when a crafted IP-TFS AGGFRAG payload is delivered to that IPTFS SA.
What input condition triggers the out-of-bounds read?
The fragment-walk offset must be at or beyond the total length covered by the walk's fragments. In the affected caller, the fragment index is advanced past the fragment count and the fixed-size on-stack fragment array is then read out of bounds.