CVE-2026-46273
published 2026-06-03CVE-2026-46273: In the Linux kernel, the following vulnerability has been resolved: ibmveth: Disable GSO for packets with small MSS Some physical adapters on Power systems do…
PriorityP346high8.6CVSS 3.1
AVNACLPRNUINSCCNINAH
EPSS
0.39%
31.2th percentile
In the Linux kernel, the following vulnerability has been resolved:
ibmveth: Disable GSO for packets with small MSS
Some physical adapters on Power systems do not support segmentation
offload when the MSS is less than 224 bytes. Attempting to send such
packets causes the adapter to freeze, stopping all traffic until
manually reset.
Implement ndo_features_check to disable GSO for packets with small MSS
values. The network stack will perform software segmentation instead.
The 224-byte minimum matches ibmvnic
commit ("ibmvnic: Enforce stronger sanity checks
on GSO packets")
which uses the same physical adapters in SEA configurations.
The issue occurs specifically when the hardware attempts to perform
segmentation (gso_segs > 1) with a small MSS. Single-segment GSO packets
(gso_segs == 1) do not trigger the problematic LSO code path and are
transmitted normally without segmentation.
Add an ndo_features_check callback to disable GSO when MSS < 224 bytes.
Also call vlan_features_check() to ensure proper handling of VLAN packets,
particularly QinQ (802.1ad) configurations where the hardware parser may
not support certain offload features.
Validated using iptables to force small MSS values. Without the fix,
the adapter freezes. With the fix, packets are segmented in software
and transmission succeeds. Comprehensive regression testing completedd
(MSS tests, performance, stability).
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| linux | linux | — | — |
| linux | linux | >= 8641dd85799f85bef5f0d1f87356aaa12cb2195e < 86fc64584811d43c9ccd74447de58620189d8b77 | 86fc64584811d43c9ccd74447de58620189d8b77 |
| linux | linux | >= 8641dd85799f85bef5f0d1f87356aaa12cb2195e < 9a5e984d7af910e46dcbed3ce77873e000a4f77d | 9a5e984d7af910e46dcbed3ce77873e000a4f77d |
| linux | linux | >= 8641dd85799f85bef5f0d1f87356aaa12cb2195e < 1cdf5dbcec988d06f5f720bdf89e91073f77fa10 | 1cdf5dbcec988d06f5f720bdf89e91073f77fa10 |
| linux | linux | >= 8641dd85799f85bef5f0d1f87356aaa12cb2195e < 82bc89fbb82d9396fb4eaee8720ea85e2e787957 | 82bc89fbb82d9396fb4eaee8720ea85e2e787957 |
| linux | linux | >= 8641dd85799f85bef5f0d1f87356aaa12cb2195e < db8012c631cb845e9ae2b4b531e17d86c9519755 | db8012c631cb845e9ae2b4b531e17d86c9519755 |
| linux | linux | >= 8641dd85799f85bef5f0d1f87356aaa12cb2195e < c1f261863e65b508f37416dfbc5c5d911c9b9233 | c1f261863e65b508f37416dfbc5c5d911c9b9233 |
| linux | linux | >= 8641dd85799f85bef5f0d1f87356aaa12cb2195e < 3af24f0c4c31f18a4a2d927990759194832bb6e9 | 3af24f0c4c31f18a4a2d927990759194832bb6e9 |
| linux | linux | >= 8641dd85799f85bef5f0d1f87356aaa12cb2195e < cc427d24ac6442ffdeafd157a63c7c5b73ed4de4 | cc427d24ac6442ffdeafd157a63c7c5b73ed4de4 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 4.2 < 5.10.258 | 5.10.258 |
| linux | linux_kernel | >= 5.11 < 5.15.209 | 5.15.209 |
| linux | linux_kernel | >= 5.16 < 6.1.175 | 6.1.175 |
| linux | linux_kernel | >= 6.13 < 6.18.30 | 6.18.30 |
| linux | linux_kernel | >= 6.19 < 7.0.7 | 7.0.7 |
| linux | linux_kernel | >= 6.2 < 6.6.140 | 6.6.140 |
| linux | linux_kernel | >= 6.7 < 6.12.88 | 6.12.88 |
CVSS provenance
nvdv3.18.6HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
In the Linux kernel, the following vulnerability has been resolved: ibmveth: Disable GSO for packets with small MSS Some physical adapters on Power systems do not support segmentation offload when t
ghsa_unreviewed·2026-06-03
CVE-2026-46273 In the Linux kernel, the following vulnerability has been resolved: ibmveth: Disable GSO for packets with small MSS Some physical adapters on Power systems do not support segmentation offload when t
In the Linux kernel, the following vulnerability has been resolved:
ibmveth: Disable GSO for packets with small MSS
Some physical adapters on Power systems do not support segmentation
offload when the MSS is less than 224 bytes. Attempting to send such
packets causes the adapter to freeze, stopping all traffic until
manually reset.
Implement ndo_features_check to disable GSO for packets with small MSS
values. The network stack will perform software segmentation instead.
The 224-byte minimum matches ibmvnic
commit ("ibmvnic: Enforce stronger sanity checks
on GSO packets")
which uses the same physical adapters in SEA configurations.
The issue occurs specifically when the hardware attempts to perform
segmentation (gso_segs > 1) with a small MSS. Single-segment GSO packets
(gso_segs == 1)
VulDB
Linux Kernel up to 7.1-rc1 ibmveth vlan_features_check stack-based overflow
vuldb·2026-06-03
CVE-2026-46273 [CRITICAL] Linux Kernel up to 7.1-rc1 ibmveth vlan_features_check stack-based overflow
A vulnerability identified as critical has been detected in Linux Kernel up to 7.1-rc1. The affected element is the function vlan_features_check of the component ibmveth. This manipulation causes stack-based buffer overflow.
The identification of this vulnerability is CVE-2026-46273. The attack needs to be done within the local network. There is no exploit available.
You should upgrade the affected component.
Red Hat
kernel: ibmveth: Disable GSO for packets with small MSS
vendor_redhat·2026-06-03·CVSS 5.5
CVE-2026-46273 [MEDIUM] CWE-1284 kernel: ibmveth: Disable GSO for packets with small MSS
kernel: ibmveth: Disable GSO for packets with small MSS
A flaw was found in the Linux kernel's ibmveth driver. This vulnerability occurs when physical adapters on Power systems attempt to perform Generic Segmentation Offload (GSO) with a Maximum Segment Size (MSS) less than 224 bytes. A remote attacker could exploit this by sending specially crafted network packets, leading to the adapter freezing and a complete Denial of Service (DoS) for all network traffic until a manual reset.
Package: kernel (Red Hat Enterprise Linux 10) - Fix deferred
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Fix deferred
Package: kernel-rt (Red Hat Enterprise Linux 7) - Fix deferred
Package: kernel (Red Hat Enterprise Linux 8) - Fix deferred
Pac
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/1cdf5dbcec988d06f5f720bdf89e91073f77fa10https://git.kernel.org/stable/c/3af24f0c4c31f18a4a2d927990759194832bb6e9https://git.kernel.org/stable/c/82bc89fbb82d9396fb4eaee8720ea85e2e787957https://git.kernel.org/stable/c/86fc64584811d43c9ccd74447de58620189d8b77https://git.kernel.org/stable/c/9a5e984d7af910e46dcbed3ce77873e000a4f77dhttps://git.kernel.org/stable/c/c1f261863e65b508f37416dfbc5c5d911c9b9233https://git.kernel.org/stable/c/cc427d24ac6442ffdeafd157a63c7c5b73ed4de4https://git.kernel.org/stable/c/db8012c631cb845e9ae2b4b531e17d86c9519755
2026-06-03
Published