{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-80725","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-08-26T14:34:25.789Z","datePublished":"2026-08-29T06:39:35.212Z","dateUpdated":"2026-09-04T04:58:15.396Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-04T04:58:15.396Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: gro: properly validate BIG TCP aggregation criteria\n\nWhen GRO attempts to aggregate packets beyond GRO_LEGACY_MAX_SIZE (64KB),\nBIG TCP should only be permitted for plain IPv4 TCP and plain IPv6 TCP\n(with sufficient MAC header room to insert the temporary HBH jumbo header).\n\nHowever, commit b1a78b9b9886 (\"net: add support for ipv4 big tcp\")\nloosened the check in skb_gro_receive(), leading to several issues:\n\n1. skb_gro_receive() checked skb_headroom(p) instead of the actual space\n   before the MAC header (p->mac_header). Because skb_headroom(p) includes\n   mac_len, crafted frames (e.g. injected via AF_PACKET) can pass the check\n   with p->mac_header < 8 bytes. When ipv6_gro_complete() inserts the\n   temporary HBH jumbo header, the memmove() starts before skb->head,\n   causing an out-of-bounds write and wrapping skb->mac_header.\n2. It allowed non-IP protocols such as software VLAN (ETH_P_8021Q /\n   ETH_P_8021AD) to aggregate beyond 64KB because\n   p->protocol != ETH_P_IPV6 was true.\n3. It checked p->encapsulation instead of NAPI_GRO_CB(skb)->encap_mark,\n   allowing encapsulated flows (e.g. SIT / IPv6-in-IPv4) to aggregate\n   beyond 64KB.\n\nFix skb_gro_receive() to strictly enforce:\n- NAPI_GRO_CB(skb)->proto == IPPROTO_TCP\n- Not encapsulated (!NAPI_GRO_CB(skb)->encap_mark && !p->encapsulation)\n- Protocol must be either ETH_P_IP or ETH_P_IPV6\n- If ETH_P_IPV6, p->mac_header must be at least\n  sizeof(struct hop_jumbo_hdr)\n\nReturning -E2BIG from skb_gro_receive() ensures that packets which cannot\nbecome BIG TCP are cleanly flushed at <= 64KB and delivered intact without\ndropping.\n\nThis issue does not exist in mainline (7.0+) because the subsystem was\nrewritten in commit 81be30c1f5f2 (\"net/ipv6: Drop HBH for BIG TCP on RX\nside\"), making this fix relevant only for older stable branches like\n6.18.y."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL"},"scenarios":[{"lang":"en","value":"AV:N - The flaw is in skb_gro_receive() on the netdev NAPI GRO ingress path (netif_receive_skb→napi_gro_receive→dev_gro_receive→tcp/ipv6 gro handlers); remote peers can deliver crafted in-flow TCP streams to internet-facing interfaces without local access.\nAC:L - On Big TCP deployments with gro_max_size>64KB, an attacker reliably coalesces past GRO_LEGACY_MAX_SIZE by sending many same-flow TCP segments; AF_PACKET injection also gives deterministic header layout control without races or victim-dependent heap layout.\nPR:N - RX GRO runs in softirq on all received packets before socket authentication; no target credentials or capabilities are required. Elevated gro_max_size is an admin tuning prerequisite of the Big TCP server class, not an attacker privilege.\nUI:N - Packet reception and GRO aggregation are automatic kernel network-stack processing triggered solely by attacker-sent traffic; no victim mount, file open, or other interaction is required.\nS:U - Impact is kernel skb/heap memory corruption within the host kernel security authority; exploitation does not cross VM, container, or IOMMU boundaries that would warrant scope-changed scoring.\nC:H - When undersized mac_header room passes the broken skb_headroom check, ipv6_gro_complete() memmove() for the temporary HBH jumbo header writes before skb->head, corrupting adjacent kernel memory and enabling information disclosure from attacker-influenced out-of-bounds writes.\nI:H - The same invalid BIG TCP aggregation drives attacker-controlled memmove/header corruption that wraps skb->mac_header, yielding an out-of-bounds write primitive suitable for heap object corruption, control-flow hijacking, and local privilege escalation.\nA:H - The defective memmove or invalid >64KB aggregation on disallowed VLAN, encapsulated, or malformed flows can oops or panic the kernel during GRO completion, and a remote attacker can trigger this repeatedly to deny service."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/core/gro.c"],"versions":[{"version":"0fe79f28bfaf73b66b7b1562d2468f94aa03bd12","lessThan":"37a5dcd6837fc2afc44a7bc3ed8af4e983783d46","status":"affected","versionType":"git"},{"version":"0fe79f28bfaf73b66b7b1562d2468f94aa03bd12","lessThan":"e907bf694ed55bdfe421be99dba35751a655df25","status":"affected","versionType":"git"},{"version":"0fe79f28bfaf73b66b7b1562d2468f94aa03bd12","lessThan":"03cb8cc2961f5f781d12e903782cb3815ed84b1c","status":"affected","versionType":"git"},{"version":"0fe79f28bfaf73b66b7b1562d2468f94aa03bd12","lessThan":"3ce832e2bd431d0c12ba525ed73ad8fbc4191da5","status":"affected","versionType":"git"},{"version":"0fe79f28bfaf73b66b7b1562d2468f94aa03bd12","lessThan":"81be30c1f5f2bffda1f04c0efd0746af10b9643a","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/core/gro.c"],"versions":[{"version":"5.19","status":"affected"},{"version":"0","lessThan":"5.19","status":"unaffected","versionType":"semver"},{"version":"6.1.185","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.154","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.106","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.47","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.0","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.19","versionEndExcluding":"6.1.185"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.19","versionEndExcluding":"6.6.154"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.19","versionEndExcluding":"6.12.106"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.19","versionEndExcluding":"6.18.47"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.19","versionEndExcluding":"7.0"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/37a5dcd6837fc2afc44a7bc3ed8af4e983783d46"},{"url":"https://git.kernel.org/stable/c/e907bf694ed55bdfe421be99dba35751a655df25"},{"url":"https://git.kernel.org/stable/c/03cb8cc2961f5f781d12e903782cb3815ed84b1c"},{"url":"https://git.kernel.org/stable/c/3ce832e2bd431d0c12ba525ed73ad8fbc4191da5"},{"url":"https://git.kernel.org/stable/c/81be30c1f5f2bffda1f04c0efd0746af10b9643a"}],"title":"net: gro: properly validate BIG TCP aggregation criteria","x_generator":{"engine":"bippy-1.2.0"}}}}