AI analysis
CVE-2026-98375 is a flaw in the Linux kernel Xen paravirtual network frontend, xen-netfront. handle_incoming_queue() copies the first RX slot from the backend, capped at RX_COPY_THRESHOLD, into the socket-buffer head and then calls eth_type_trans() without checking that at least an Ethernet header (ETH_HLEN) is present. If that first slot is shorter than ETH_HLEN and more slots follow, the guest BUG()s in __skb_pull(); if the whole packet is shorter than ETH_HLEN, eth_type_trans() reads the header past the end of the packet data. A Xen backend (typically dom0 or a driver domain) can therefore crash the Linux guest; this is not reachable by an unprivileged remote attacker on non-Xen hosts. No public proof of concept is known, the issue is not in CISA KEV, and exploitation in the wild is not reported.
What to do: Install a distribution kernel that includes the xen-netfront fix from XSA-522 / CVE-2026-98375 and reboot affected guests so the new driver is loaded. Until then, treat dom0 and any Xen network driver domain as trusted, because a compromised or malicious backend can crash the guest with malformed RX packets. The supplied data names no fixed version, so match the patch to your distro advisory rather than assuming a version number.
Affected
| Linux kernel (xen-netfront) | — |
Estimated exposure
nicheNo basis for an estimate.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
In the Linux kernel, the following vulnerability has been resolved: xen/netfront: drop RX packets with a short Ethernet header handle_incoming_queue() pulls pull_to bytes into the head before calling eth_type_trans(). pull_to is the length of the first RX slot, capped at RX_COPY_THRESHOLD, and that length comes from the backend. Nothing checks it against ETH_HLEN. If the first slot is shorter than ETH_HLEN and more slots follow, the head ends up shorter than an Ethernet header while skb->len is longer, and eth_type_trans() BUG()s in __skb_pull(). If the whole packet is shorter than ETH_HLEN, eth_type_trans() reads the header past the end of the data instead. Pull at least ETH_HLEN, and drop the packet if that fails, which also drops packets too short to hold an Ethernet header. This also checks the return value of the pull, which was ignored.