Description
In the Linux kernel, the following vulnerability has been resolved:

net/openvswitch: check Ethernet header length in key_extract()

When a packet arrives on an ARPHRD_NONE device (e.g. TUN),
ovs_flow_key_extract() trusts the user-provided skb->protocol field: if
it is ETH_P_TEB, the packet is classified as MAC_PROTO_ETHERNET and
key_extract() is called without ensuring the skb has ETH_HLEN (14) bytes
of linear data. key_extract() unconditionally pulls 2 * ETH_ALEN bytes
for MAC addresses and parse_ethertype() pulls 2 more, either of which
triggers a kernel BUG in __skb_pull() when the linear area is too small.

kernel BUG at include/linux/skbuff.h:2848!
RIP: 0010:key_extract+0xa7e/0xd90 net/openvswitch/flow.c:933
ovs_flow_key_extract+0x419/0xa70
ovs_vport_receive+0x222/0x390
netdev_frame_hook+0x3e0/0x630
tun_get_user+0x2d0c/0x38e0

Fixed by calling check_header() in key_extract() before accessing the
Ethernet header.
Published: 2026-08-22
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via kernel crash
Action: Immediate Patch
AI Analysis

Impact

The Linux kernel allowed a packet received on an ARPHRD_NONE device, such as a TUN interface, to be processed by key_extract() without verifying that the packet contained at least the expected 14 bytes of Ethernet header data. This omission meant that when the skb->protocol field was set to ETH_P_TEB, the kernel attempted to pull 2×ETH_ALEN bytes for MAC addresses and an additional 2 bytes for the ethertype, which triggered a BUG in __skb_pull() and caused a kernel crash. The result is a denial of service, potentially affecting system availability when a misconstructed packet is received. The likely attack vector involves local or privileged access to inject malformed packets into an ARPHRD_NONE device.

Affected Systems

All Linux kernel builds that include the openvswitch network subsystem and support ARPHRD_NONE devices are impacted, including any release that has not incorporated the fix that adds a check_header() call before accessing the Ethernet header. The issue manifests on systems that create or use TUN/TAP interfaces or other devices that expose the ARPHRD_NONE type.

Risk and Exploitability

The CVSS score of 7.8 marks this vulnerability as high severity. The likely attack vector involves local or privileged access to inject malformed packets into an ARPHRD_NONE device, after which a crafted packet can trigger a kernel BUG, causing a system crash and resulting in denial of service. The EPSS score is present but below 1%, indicating a very low probability of exploitation in the wild. It is not listed in CISA KEV, so no known widespread exploitation cases exist. Systems exposing TUN/TAP interfaces to untrusted users remain at elevated risk until the bug is addressed.

Generated by OpenCVE AI on August 25, 2026 at 13:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest kernel update that implements the check_header() call in key_extract()
  • Restrict the creation and use of ARPHRD_NONE interfaces such as TUN to privileged users until the patch is deployed
  • Disable unused TUN/TAP interfaces or carefully audit their usage to reduce attack surface

Generated by OpenCVE AI on August 25, 2026 at 13:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4777-1 linux security update
Debian DSA Debian DSA DSA-6466-1 linux security update
History

Tue, 25 Aug 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
References
Metrics threat_severity

None

threat_severity

Moderate


Tue, 25 Aug 2026 11:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-788

Tue, 25 Aug 2026 09:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
CWE-20

Tue, 25 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Sat, 22 Aug 2026 19:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
CWE-20

Sat, 22 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: net/openvswitch: check Ethernet header length in key_extract() When a packet arrives on an ARPHRD_NONE device (e.g. TUN), ovs_flow_key_extract() trusts the user-provided skb->protocol field: if it is ETH_P_TEB, the packet is classified as MAC_PROTO_ETHERNET and key_extract() is called without ensuring the skb has ETH_HLEN (14) bytes of linear data. key_extract() unconditionally pulls 2 * ETH_ALEN bytes for MAC addresses and parse_ethertype() pulls 2 more, either of which triggers a kernel BUG in __skb_pull() when the linear area is too small. kernel BUG at include/linux/skbuff.h:2848! RIP: 0010:key_extract+0xa7e/0xd90 net/openvswitch/flow.c:933 ovs_flow_key_extract+0x419/0xa70 ovs_vport_receive+0x222/0x390 netdev_frame_hook+0x3e0/0x630 tun_get_user+0x2d0c/0x38e0 Fixed by calling check_header() in key_extract() before accessing the Ethernet header.
Title net/openvswitch: check Ethernet header length in key_extract()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-25T05:41:43.778Z

Reserved: 2026-08-15T05:44:03.927Z

Link: CVE-2026-74701

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-22T16:16:44.740

Modified: 2026-08-25T06:18:53.827

Link: CVE-2026-74701

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-22T00:00:00Z

Links: CVE-2026-74701 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T14:00:17Z

Weaknesses
  • CWE-125

    Out-of-bounds Read

  • CWE-788

    Access of Memory Location After End of Buffer