cbcvebase.
CVE-2026-45840
published 2026-05-27

CVE-2026-45840: In the Linux kernel, the following vulnerability has been resolved: openvswitch: cap upcall PID array size and pre-size vport replies The vport netlink reply…

high7
In the Linux kernel, the following vulnerability has been resolved: openvswitch: cap upcall PID array size and pre-size vport replies The vport netlink reply helpers allocate a fixed-size skb with nlmsg_new(NLMSG_DEFAULT_SIZE, ...) but serialize the full upcall PID array via ovs_vport_get_upcall_portids(). Since ovs_vport_set_upcall_portids() accepts any non-zero multiple of sizeof(u32) with no upper bound, a CAP_NET_ADMIN user can install a PID array large enough to overflow the reply buffer, causing nla_put() to fail with -EMSGSIZE and hitting BUG_ON(err genl_family_rcv_msg_doit (net/netlink/genetlink.c:1116) genl_rcv_msg (net/netlink/genetlink.c:1194) netlink_rcv_skb (net/netlink/af_netlink.c:2550) genl_rcv (net/netlink/genetlink.c:1219) netlink_unicast (net/netlink/af_netlink.c:1344) netlink_sendmsg (net/netlink/af_netlink.c:1894) __sys_sendto (net/socket.c:2206) __x64_sys_sendto (net/socket.c:2209) do_syscall_64 (arch/x86/entry/syscall_64.c:63) entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:130) Kernel panic - not syncing: Fatal exception Reject attempts to set more PIDs than nr_cpu_ids in ovs_vport_set_upcall_portids(), and pre-compute the worst-case reply size in ovs_vport_cmd_msg_size() based on that bound, similar to the existing ovs_dp_cmd_msg_size(). nr_cpu_ids matches the cap already used by the per-CPU dispatch configuration on the datapath side (ovs_dp_cmd_fill_info() serialises at most nr_cpu_ids PIDs), so the two sides stay consistent.

Affected

10 ranges
VendorProductVersion rangeFixed in
linuxlinux
linuxlinux>= 5cd667b0a4567048bb555927d6ee564f4e5620a9 < 8d59b80e69dddb665eb2de36e62859ab2073470e8d59b80e69dddb665eb2de36e62859ab2073470e
linuxlinux>= 5cd667b0a4567048bb555927d6ee564f4e5620a9 < d9e47e29aacb9f8a9d59feb6ab5b128a9bbb40b0d9e47e29aacb9f8a9d59feb6ab5b128a9bbb40b0
linuxlinux>= 5cd667b0a4567048bb555927d6ee564f4e5620a9 < b39f763d720d623218bc1d95ace6855d7b474e81b39f763d720d623218bc1d95ace6855d7b474e81
linuxlinux>= 5cd667b0a4567048bb555927d6ee564f4e5620a9 < f9ef3db77a383d66847fd082c2b437d8ae4d9c63f9ef3db77a383d66847fd082c2b437d8ae4d9c63
linuxlinux>= 5cd667b0a4567048bb555927d6ee564f4e5620a9 < f99ac36b5d7c719d08a69fcdecce40f78a874e15f99ac36b5d7c719d08a69fcdecce40f78a874e15
linuxlinux>= 5cd667b0a4567048bb555927d6ee564f4e5620a9 < fa6e90bc443bed8dc0d55bc5ea5b27ffdfe37704fa6e90bc443bed8dc0d55bc5ea5b27ffdfe37704
linuxlinux>= 5cd667b0a4567048bb555927d6ee564f4e5620a9 < 1d6c02b86329883aa467a3a61f8d34369db73a2f1d6c02b86329883aa467a3a61f8d34369db73a2f
linuxlinux>= 5cd667b0a4567048bb555927d6ee564f4e5620a9 < 2091c6aa0df6aba47deb5c8ab232b1cb60af35192091c6aa0df6aba47deb5c8ab232b1cb60af3519
linuxlinux_kernel