Description
In the Linux kernel, the following vulnerability has been resolved:

lwt_bpf: Restore reserved headroom after xmit program

ip_finish_output2() expands an skb to LL_RESERVED_SPACE(dev) before LWT
xmit. An LWT_XMIT BPF program can then modify the skb head and still
return BPF_OK, so bpf_xmit() rechecks the remaining headroom before the
skb continues to neighbour output.

That recheck uses dst->dev->hard_header_len. This is not enough for the
neighbour cached-header path: neigh_hh_output() copies the cached hardware
header using the aligned hh_cache size, HH_DATA_MOD for short headers or
HH_DATA_ALIGN(hh_len) otherwise.

On Ethernet, hard_header_len is 14 but the cached copy needs 16 bytes. If
an LWT_XMIT BPF program calls bpf_skb_change_head(skb, 1, 0), the skb can
still have 15 bytes of headroom after the program. The existing check
accepts that, after which neigh_hh_output() hits its headroom warning and
drops the skb.

Use LL_RESERVED_SPACE(dst->dev) in the post-BPF headroom check to match
the reservation made before LWT xmit.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch
AI Analysis

Impact

The vulnerability in the Linux kernel’s LWT XMIT BPF path allows manipulation of sk_buff headroom during packet transmission. An attacker with the ability to load or register an LWT_XMIT BPF program can call bpf_skb_change_head to reduce the packet’s headroom, causing the post–transmission headroom check to accept an insufficient buffer. When the packet reaches neigh_hh_output, the kernel detects a headroom warning and drops the packet, resulting in loss of traffic or degraded network performance for the affected host.

Affected Systems

Linux kernel systems that have the lwt_bpf feature enabled and have not yet applied the patch to restore LL_RESERVED_SPACE usage in the post-BPF headroom check. The CVE does not specify particular kernel releases, so any kernel build before the fix is considered vulnerable.

Risk and Exploitability

The CVSS score is not provided, but the EPSS score indicates a < 1% exploitation probability, and the vulnerability is not in the CISA KEV catalog. Exploitation requires local kernel-level access to load or modify an LWT_XMIT BPF program, so the attack vector is local. The overall risk is moderate: unpatched hosts could suffer packet loss or denial of service if an attacker gains the necessary privileges, but widespread exploitation is unlikely at present.

Generated by OpenCVE AI on September 20, 2026 at 01:53 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes the patch restoring LL_RESERVED_SPACE usage in the post-BPF headroom check.
  • If an upgrade is not possible, restrict the ability to load LWT_XMIT BPF programs through kernel module permissions or disable the lwt_bpf feature entirely.
  • Monitor kernel logs for ‘neigh_hh_output headroom warning’ messages to detect attempted exploitation and investigate potential privileged code execution.

Generated by OpenCVE AI on September 20, 2026 at 01:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 20 Sep 2026 02:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: lwt_bpf: Restore reserved headroom after xmit program ip_finish_output2() expands an skb to LL_RESERVED_SPACE(dev) before LWT xmit. An LWT_XMIT BPF program can then modify the skb head and still return BPF_OK, so bpf_xmit() rechecks the remaining headroom before the skb continues to neighbour output. That recheck uses dst->dev->hard_header_len. This is not enough for the neighbour cached-header path: neigh_hh_output() copies the cached hardware header using the aligned hh_cache size, HH_DATA_MOD for short headers or HH_DATA_ALIGN(hh_len) otherwise. On Ethernet, hard_header_len is 14 but the cached copy needs 16 bytes. If an LWT_XMIT BPF program calls bpf_skb_change_head(skb, 1, 0), the skb can still have 15 bytes of headroom after the program. The existing check accepts that, after which neigh_hh_output() hits its headroom warning and drops the skb. Use LL_RESERVED_SPACE(dst->dev) in the post-BPF headroom check to match the reservation made before LWT xmit.
Title lwt_bpf: Restore reserved headroom after xmit program
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:06:51.806Z

Reserved: 2026-09-11T19:38:34.790Z

Link: CVE-2026-90160

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:09.190

Modified: 2026-09-17T17:17:09.190

Link: CVE-2026-90160

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T02:00:13Z

Weaknesses
  • CWE-20

    Improper Input Validation