CVE-2026-98375: xen/netfront: drop RX packets with a short Ethernet header

Published Oct 9, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

xen/netfront: drop RX packets with a short Ethernet header

handleincomingqueue() pulls pullto bytes into the head before calling ethtypetrans(). pullto is the length of the first RX slot, capped at RXCOPYTHRESHOLD, and that length comes from the backend. Nothing checks it against ETHHLEN.

If the first slot is shorter than ETHHLEN and more slots follow, the head ends up shorter than an Ethernet header while skb->len is longer, and ethtypetrans() BUG()s in skbpull(). If the whole packet is shorter than ETHHLEN, ethtypetrans() reads the header past the end of the data instead.

Pull at least ETHHLEN, and drop the packet if that fails, which also drops packets too short to hold an Ethernet header. This also checks the return value of the pull, which was ignored.

Affected Software

1 affected component
Linux Linux kernel

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Compensating control

    In Linux xen-netfront, ensure the first RX slot pulls at least ETH_HLEN bytes into the packet head and drop the RX packet if that pull fails, preventing packets with a short Ethernet header from reaching eth_type_trans().

Event History

Oct 9, 2026
CVE Published
via MITRE·07:10 AM
Data Sourced
via MITRE·07:10 AM
Description
Data Sourced
via NVD·08:16 AM
Description

Frequently Asked Questions

1

Which systems are exposed to this issue?

Systems using the Linux kernel Xen netfront driver are exposed when they receive packets from a Xen backend. The vulnerable path is in receive processing for that frontend driver.

2

What does an attacker need to trigger the failure?

The backend must provide a received packet whose first RX slot is shorter than an Ethernet header. If additional slots make the overall packet longer, processing can trigger a BUG() in eth_type_trans(); packets shorter than an Ethernet header can instead cause an out-of-bounds header read.

3

How can I tell whether the fix is present?

The fix ensures that at least ETH_HLEN bytes are pulled into the packet head before eth_type_trans() is called, and drops the packet if that pull fails. It also checks the previously ignored return value of the pull operation.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203