CyberRota Analysis
AI-GeneratedThe vulnerability affects the Linux kernel's handling of VXLAN (Virtual Extensible LAN) packets, specifically in the transmit path where improper checks on network layer headers can lead to incomplete data being processed. This flaw could potentially allow for data corruption or misrouting of packets, impacting network communication integrity. Organizations using Linux-based systems, particularly those implementing VXLAN for network virtualization, should prioritize patching to mitigate potential risks associated with this vulnerability.
Original NVD Description
In the Linux kernel, the following vulnerability has been resolved: vxlan: use pskb_network_may_pull() for transmit path header pulls In vxlan_xmit(), arp_reduce(), and vxlan_mdb_entry_skb_get(), pskb_may_pull() was being called to verify the availability of network layer headers (ARP, IPv6/ND, IP/IPv6 MDB keys). However, during transmit skb->data points to the MAC header, so skb_network_offset(skb) is ETH_HLEN (14 bytes). Using pskb_may_pull(skb, len) only checks len bytes from skb->data rather than skb_network_offset(skb) + len, which can leave part of the network header in non-linear frags. Replace these remaining pskb_may_pull() calls with pskb_network_may_pull() to properly account for the MAC header offset.