Description
In the Linux kernel, the following vulnerability has been resolved:

net: ife: require ETH_HLEN to be pullable in ife_decode()

ife decode may return after making only the outer IFE header and
metadata pullable. The caller then passes the decapsulated packet to
eth_type_trans(), which expects the inner Ethernet header to be
accessible from the linear data area.

With a malformed IFE frame, the inner Ethernet header may still be
shorter than ETH_HLEN in the linear area, which can lead to a crash in
the original code.

Fix this by extending the pull check in ife_decode() so that the inner
Ethernet header is also guaranteed to be pullable before returning.
Published: 2026-08-15
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The IFE (Intra‑Frame Encapsulation) decoder in the Linux kernel incorrectly marks the inner Ethernet header as available after only pulling the outer IFE header and metadata. Because the caller passes the decoded packet to eth_type_trans(), which expects the inner Ethernet header to be located in the linear part of the buffer, a malformed IFE frame can leave the inner header shorter than the required ETH_HLEN bytes in the linear area, leading to an out‑of‑bounds read and a kernel crash. This flaw manifests as a local denial‑of‑service via a system reboot or kernel panic.

Affected Systems

Affected systems are all Linux kernel implementations that expose the IFE interface. The advisory does not list specific kernel versions, implying that any kernel which implements the original IFE decoder without the recent patch is vulnerable. The vendor products are identified simply as “Linux:Linux” in the CNA data.

Risk and Exploitability

The CVSS score of 9.1 reflects the high severity of a kernel crash. The EPSS score is reported as less than 1 %, indicating a low probability of exploitation, and the vulnerability is not currently listed in the CISA KEV catalog. Based on the description, the attack vector is likely to involve the transmission of malformed IFE frames over a network interface that can receive IFE traffic. The threat requires either local access to the affected system or the ability to deliver such frames to the target interface, so attackers who can reach or manipulate the network path are most relevant.

Generated by OpenCVE AI on August 17, 2026 at 20:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Back up your system and install the latest Linux kernel release that incorporates the fixed IFE decoder code; this patch is available in the upstream commits referenced in the advisory.
  • If a kernel upgrade cannot be performed immediately, apply firewall rules on the affected interface to drop or block IFE traffic (e.g., using nftables or iptables) so that malformed IFE frames never reach the kernel.
  • As a short‑term workaround, manually apply the diff that extends the pull check in ife_decode() to the kernel source, rebuild the kernel, and install the patched module.

Generated by OpenCVE AI on August 17, 2026 at 20:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 00:15:00 +0000


Mon, 17 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-122
CWE-125

Mon, 17 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119

Mon, 17 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H'}


Sat, 15 Aug 2026 11:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119

Sat, 15 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: net: ife: require ETH_HLEN to be pullable in ife_decode() ife decode may return after making only the outer IFE header and metadata pullable. The caller then passes the decapsulated packet to eth_type_trans(), which expects the inner Ethernet header to be accessible from the linear data area. With a malformed IFE frame, the inner Ethernet header may still be shorter than ETH_HLEN in the linear area, which can lead to a crash in the original code. Fix this by extending the pull check in ife_decode() so that the inner Ethernet header is also guaranteed to be pullable before returning.
Title net: ife: require ETH_HLEN to be pullable in ife_decode()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-17T05:42:29.172Z

Reserved: 2026-08-09T03:40:39.917Z

Link: CVE-2026-72296

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-15T06:22:02.160

Modified: 2026-08-17T06:18:32.417

Link: CVE-2026-72296

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-15T00:00:00Z

Links: CVE-2026-72296 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T20:15:06Z

Weaknesses