CVE-2026-45840
published 2026-05-27CVE-2026-45840: In the Linux kernel, the following vulnerability has been resolved: openvswitch: cap upcall PID array size and pre-size vport replies The vport netlink reply…
high7
In the Linux kernel, the following vulnerability has been resolved:
openvswitch: cap upcall PID array size and pre-size vport replies
The vport netlink reply helpers allocate a fixed-size skb with
nlmsg_new(NLMSG_DEFAULT_SIZE, ...) but serialize the full upcall PID
array via ovs_vport_get_upcall_portids(). Since
ovs_vport_set_upcall_portids() accepts any non-zero multiple of
sizeof(u32) with no upper bound, a CAP_NET_ADMIN user can install a PID
array large enough to overflow the reply buffer, causing nla_put() to
fail with -EMSGSIZE and hitting BUG_ON(err
genl_family_rcv_msg_doit (net/netlink/genetlink.c:1116)
genl_rcv_msg (net/netlink/genetlink.c:1194)
netlink_rcv_skb (net/netlink/af_netlink.c:2550)
genl_rcv (net/netlink/genetlink.c:1219)
netlink_unicast (net/netlink/af_netlink.c:1344)
netlink_sendmsg (net/netlink/af_netlink.c:1894)
__sys_sendto (net/socket.c:2206)
__x64_sys_sendto (net/socket.c:2209)
do_syscall_64 (arch/x86/entry/syscall_64.c:63)
entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:130)
Kernel panic - not syncing: Fatal exception
Reject attempts to set more PIDs than nr_cpu_ids in
ovs_vport_set_upcall_portids(), and pre-compute the worst-case reply
size in ovs_vport_cmd_msg_size() based on that bound, similar to the
existing ovs_dp_cmd_msg_size(). nr_cpu_ids matches the cap already
used by the per-CPU dispatch configuration on the datapath side
(ovs_dp_cmd_fill_info() serialises at most nr_cpu_ids PIDs), so the
two sides stay consistent.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| linux | linux | — | — |
| linux | linux | >= 5cd667b0a4567048bb555927d6ee564f4e5620a9 < 8d59b80e69dddb665eb2de36e62859ab2073470e | 8d59b80e69dddb665eb2de36e62859ab2073470e |
| linux | linux | >= 5cd667b0a4567048bb555927d6ee564f4e5620a9 < d9e47e29aacb9f8a9d59feb6ab5b128a9bbb40b0 | d9e47e29aacb9f8a9d59feb6ab5b128a9bbb40b0 |
| linux | linux | >= 5cd667b0a4567048bb555927d6ee564f4e5620a9 < b39f763d720d623218bc1d95ace6855d7b474e81 | b39f763d720d623218bc1d95ace6855d7b474e81 |
| linux | linux | >= 5cd667b0a4567048bb555927d6ee564f4e5620a9 < f9ef3db77a383d66847fd082c2b437d8ae4d9c63 | f9ef3db77a383d66847fd082c2b437d8ae4d9c63 |
| linux | linux | >= 5cd667b0a4567048bb555927d6ee564f4e5620a9 < f99ac36b5d7c719d08a69fcdecce40f78a874e15 | f99ac36b5d7c719d08a69fcdecce40f78a874e15 |
| linux | linux | >= 5cd667b0a4567048bb555927d6ee564f4e5620a9 < fa6e90bc443bed8dc0d55bc5ea5b27ffdfe37704 | fa6e90bc443bed8dc0d55bc5ea5b27ffdfe37704 |
| linux | linux | >= 5cd667b0a4567048bb555927d6ee564f4e5620a9 < 1d6c02b86329883aa467a3a61f8d34369db73a2f | 1d6c02b86329883aa467a3a61f8d34369db73a2f |
| linux | linux | >= 5cd667b0a4567048bb555927d6ee564f4e5620a9 < 2091c6aa0df6aba47deb5c8ab232b1cb60af3519 | 2091c6aa0df6aba47deb5c8ab232b1cb60af3519 |
| linux | linux_kernel | — | — |