CVE-2026-98375: xen/netfront: drop RX packets with a short Ethernet header
In the Linux kernel, the following vulnerability has been resolved:
xen/netfront: drop RX packets with a short Ethernet header
handleincomingqueue() pulls pullto bytes into the head before calling ethtypetrans(). pullto is the length of the first RX slot, capped at RXCOPYTHRESHOLD, and that length comes from the backend. Nothing checks it against ETHHLEN.
If the first slot is shorter than ETHHLEN and more slots follow, the head ends up shorter than an Ethernet header while skb->len is longer, and ethtypetrans() BUG()s in skbpull(). If the whole packet is shorter than ETHHLEN, ethtypetrans() reads the header past the end of the data instead.
Pull at least ETHHLEN, and drop the packet if that fails, which also drops packets too short to hold an Ethernet header. This also checks the return value of the pull, which was ignored.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
In Linux xen-netfront, ensure the first RX slot pulls at least ETH_HLEN bytes into the packet head and drop the RX packet if that pull fails, preventing packets with a short Ethernet header from reaching eth_type_trans().
Event History
Frequently Asked Questions
Which systems are exposed to this issue?
Systems using the Linux kernel Xen netfront driver are exposed when they receive packets from a Xen backend. The vulnerable path is in receive processing for that frontend driver.
What does an attacker need to trigger the failure?
The backend must provide a received packet whose first RX slot is shorter than an Ethernet header. If additional slots make the overall packet longer, processing can trigger a BUG() in eth_type_trans(); packets shorter than an Ethernet header can instead cause an out-of-bounds header read.
How can I tell whether the fix is present?
The fix ensures that at least ETH_HLEN bytes are pulled into the packet head before eth_type_trans() is called, and drops the packet if that pull fails. It also checks the previously ignored return value of the pull operation.