Fedora Account System
Red Hat Associate
Red Hat Customer
In the Linux kernel, the following vulnerability has been resolved: net: pull headers in qdisc_pkt_len_segs_init() Most ndo_start_xmit() methods expects headers of gso packets to be already in skb->head. net/core/tso.c users are particularly at risk, because tso_build_hdr() does a memcpy(hdr, skb->data, hdr_len); qdisc_pkt_len_segs_init() already does a dissection of gso packets. Use pskb_may_pull() instead of skb_header_pointer() to make sure drivers do not have to reimplement this. Some malicious packets could be fed, detect them so that we can drop them sooner with a new SKB_DROP_REASON_SKB_BAD_GSO drop_reason.
Upstream advisory: https://lore.kernel.org/linux-cve-announce/2026062409-CVE-2026-53091-cb58@gregkh/T
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:65334 https://access.redhat.com/errata/RHSA-2026:65334
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:66324 https://access.redhat.com/errata/RHSA-2026:66324
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:66325 https://access.redhat.com/errata/RHSA-2026:66325
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:67150 https://access.redhat.com/errata/RHSA-2026:67150
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions Via RHSA-2026:73645 https://access.redhat.com/errata/RHSA-2026:73645
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:74174 https://access.redhat.com/errata/RHSA-2026:74174