Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.kernel > #93926
| Path | csiph.com!fu-berlin.de!bofh.it!news.nic.it!robomod |
|---|---|
| From | Daniel Pereira <danielmaraboo@gmail.com> |
| Newsgroups | linux.debian.bugs.dist, linux.debian.kernel |
| Subject | Bug#1146105: [PATCH v2] src:linux: CVE-2026-80725 backport for bookworm |
| Date | Sun, 30 Aug 2026 06:30:01 +0200 |
| Message-ID | <NxFl7-e5W5-1@gated-at.bofh.it> (permalink) |
| References | <NxyCZ-e272-1@gated-at.bofh.it> |
| X-Original-To | 1146105@bugs.debian.org |
| X-Mailbox-Line | From debian-bugs-dist-request@lists.debian.org Sun Aug 30 04:21:09 2026 |
| Old-Return-Path | <debbugs@buxtehude.debian.org> |
| X-Spam-Flag | NO |
| X-Spam-Score | -0.548 |
| Reply-To | Daniel Pereira <danielmaraboo@gmail.com>, 1146105@bugs.debian.org |
| Resent-To | debian-bugs-dist@lists.debian.org |
| Resent-Cc | debian-kernel@lists.debian.org |
| X-Debian-Pr-Message | followup 1146105 |
| X-Debian-Pr-Package | src:linux |
| X-Debian-Pr-Keywords | patch security |
| X-Debian-Pr-Source | linux |
| X-Gm-Message-State | AFuF++nkEcNltVdyLIpI0n8QqynSrldA937DTdQi1onRji+WsnrpASuC 0zxEUqx8ARwBuFKcuGLDZCZ4Y7LMqmvuEA1keD1VgotPToQL9u7N5m3NP9lsrkRG |
| X-Gm-Gg | AYBFou3XXZYk/QuZGJxZip73yWHsy82AT3VDkICOKTbKlo3br+tcbDfGwaUevMF0zIL fMQKArOfXjmnFxI0OYekE3xT85RyL1QtRcDy6EYOz8E0tyF9tpbih47dn9volleeZlyqjhtKfIE ZkpLFfIj5FdP0qpe42+7pBrUZnNIoT3hdVF+fiFGk4m5016jF3ELR/CpXiqaioV8ZFiHv/fQI/A T2KqGg8bmjrRRS1eW7IqR5NMoLXfJtl8yIRAOxCLhBk8kmKHUAzOqsfuQZb1+FNfu/apretMysw qIjBNkIbd+3vGK6QYpeEMKbB3zTbOZ3wlZCAvSRVyQN6JDMbDJMBe2tpCKIm0PfM4YD6AhEmok4 cT6StwcK9XcUqZsx9w2+4VGso9L1hdSTjLsvy+sVDskCmt2hsEIBN/t1MNotRWtVHxRbkQ7JXdB y69NbaWmuDY835ZwkuTzWiRewb3XfLgymU9E3s7h/uvhVutA9Zp9sgWc8ObClUtCVBnzRJEaZ0z w4gqo/AXtCLfHn63EoHQMj/8fyOGwRttAuANQeLTvvuL/kWF/zxhX7tNS8NjqtCIiYgEw2930vE Fa7ZoFQxIzl7Fw== |
| X-Received | by 2002:a17:903:fad:b0:2c9:c991:3bf0 with SMTP id d9443c01a7336-2d74dcc2d3cmr290942345ad.8.1788063506027; Sat, 29 Aug 2026 21:18:26 -0700 (PDT) |
| X-Mailer | git-send-email 2.47.3 |
| MIME-Version | 1.0 |
| Content-Transfer-Encoding | 8bit |
| X-Debian-Message | from BTS |
| X-Mailing-List | <debian-bugs-dist@lists.debian.org> archive/latest/1987971 |
| List-ID | <debian-bugs-dist.lists.debian.org> |
| List-URL | <https://lists.debian.org/debian-bugs-dist/> |
| Approved | robomod@news.nic.it |
| Lines | 85 |
| Organization | linux.* mail to news gateway |
| Sender | robomod@news.nic.it |
| X-Original-Date | Sun, 30 Aug 2026 01:18:19 -0300 |
| X-Original-Message-ID | <20260830041820.167702-1-danielmaraboo@gmail.com> |
| X-Original-References | <20260829211445.111220-1-danielmaraboo@gmail.com> |
| Xref | csiph.com linux.debian.bugs.dist:1306987 linux.debian.kernel:93926 |
Cross-posted to 2 groups.
Show key headers only | View raw
Package: src:linux
Version: 6.1.180-1
Severity: important
Tags: patch security
Dear Debian Kernel Team,
I noticed that CVE-2026-80725 is currently vulnerable in Debian Bookworm (6.1.x), although it has been fixed in Sid and upstream.
I have prepared and tested a backport of the upstream fix (commit 81be30c1f5f2bffda1f04c0efd0746af10b9643a) for the 6.1 kernel tree.
---
Changes in v2:
- Removed unused 'payload_len' variable in ipv6_gro_complete to fix -Werror build failure.
From: Alice Mikityanska <alice@isovalent.com>
Date: Thu, 5 Feb 2026 15:39:16 +0200
Subject: net/ipv6: Drop HBH for BIG TCP on RX side
Origin: upstream, https://git.kernel.org/linus/81be30c1f5f2bffda1f04c0efd0746af10b9643a
Bug-Debian: https://security-tracker.debian.org/tracker/CVE-2026-80725
Description: Complementary to the previous commit, stop inserting HBH when building
BIG TCP GRO SKBs.
[ Daniel Pereira ] Backported to 6.1 by removing memmove in ip6_offload.c
and adjusting iph->payload_len logic to match 6.1 context.
Index: linux-6.1.176/net/core/gro.c
===================================================================
--- linux-6.1.176.orig/net/core/gro.c
+++ linux-6.1.176/net/core/gro.c
@@ -182,7 +182,6 @@ int skb_gro_receive(struct sk_buff *p, s
if (unlikely(p->len + len >= GRO_LEGACY_MAX_SIZE)) {
if (p->protocol != htons(ETH_P_IPV6) ||
- skb_headroom(p) < sizeof(struct hop_jumbo_hdr) ||
ipv6_hdr(p)->nexthdr != IPPROTO_TCP ||
p->encapsulation)
return -E2BIG;
Index: linux-6.1.176/net/ipv6/ip6_offload.c
===================================================================
--- linux-6.1.176.orig/net/ipv6/ip6_offload.c
+++ linux-6.1.176/net/ipv6/ip6_offload.c
@@ -344,40 +344,13 @@ INDIRECT_CALLABLE_SCOPE int ipv6_gro_complete(struct sk_buff *skb, int nhoff)
{
const struct net_offload *ops;
struct ipv6hdr *iph;
int err = -ENOSYS;
- u32 payload_len;
if (skb->encapsulation) {
skb_set_inner_protocol(skb, cpu_to_be16(ETH_P_IPV6));
skb_set_inner_network_header(skb, nhoff);
}
- payload_len = skb->len - nhoff - sizeof(*iph);
- if (unlikely(payload_len > IPV6_MAXPLEN)) {
- struct hop_jumbo_hdr *hop_jumbo;
- int hoplen = sizeof(*hop_jumbo);
-
- /* Move network header left */
- memmove(skb_mac_header(skb) - hoplen, skb_mac_header(skb),
- skb->transport_header - skb->mac_header);
- skb->data -= hoplen;
- skb->len += hoplen;
- skb->mac_header -= hoplen;
- skb->network_header -= hoplen;
- iph = (struct ipv6hdr *)(skb->data + nhoff);
- hop_jumbo = (struct hop_jumbo_hdr *)(iph + 1);
-
- /* Build hop-by-hop options */
- hop_jumbo->nexthdr = iph->nexthdr;
- hop_jumbo->hdrlen = 0;
- hop_jumbo->tlv_type = IPV6_TLV_JUMBO;
- hop_jumbo->tlv_len = 4;
- hop_jumbo->jumbo_payload_len = htonl(payload_len + hoplen);
-
- iph->nexthdr = NEXTHDR_HOP;
- iph->payload_len = 0;
- } else {
- iph = (struct ipv6hdr *)(skb->data + nhoff);
- iph->payload_len = htons(payload_len);
- }
+ iph = (struct ipv6hdr *)(skb->data + nhoff);
+ iph->payload_len = htons(skb->len - nhoff - sizeof(*iph));
nhoff += sizeof(*iph) + ipv6_exthdrs_len(iph, &ops);
if (WARN_ON(!ops || !ops->callbacks.gro_complete))
Back to linux.debian.kernel | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
Bug#1146105: [PATCH] src:linux: CVE-2026-80725 backport for bookworm Daniel Pereira <danielmaraboo@gmail.com> - 2026-08-29 23:20 +0200 Bug#1146105: [PATCH v2] src:linux: CVE-2026-80725 backport for bookworm Daniel Pereira <danielmaraboo@gmail.com> - 2026-08-30 06:30 +0200 Bug#1146105: marked as done ([PATCH] src:linux: CVE-2026-80725 backport for bookworm) "Debian Bug Tracking System" <owner@bugs.debian.org> - 2026-08-30 06:40 +0200
csiph-web