Xen Security Advisory 522 v1 (CVE-2026-98375) - Linux xen-netfront: backend can crash guest via malformed RX packets
Xen XSA-522 warns a malicious backend can crash Linux guests via malformed xen-netfront packets, CVE-2026-98375.
Xen Security Advisory 522 describes CVE-2026-98375 in the Linux xen-netfront driver. If a backend splits an RX packet so the first slot is shorter than an Ethernet header, a BUG() crashes the guest. Xen characterizes the issue as a backend-induced denial of service. The published text does not say the flaw is being exploited.
- CVE-2026-98375 is published as Xen advisory XSA-522.
- A too-short first RX slot triggers BUG() in Linux xen-netfront.
- Impact is a backend-induced denial of service against the guest.
- The posted advisory does not report active exploitation.
Vulnerabilities mentionedAll →
- Linux xen-netfront guest crash via short RX headerspublished · Linux kernel (xen-netfront)
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-98375 | Linux xen-netfront guest crash via short RX headers CVE-2026-98375 is a flaw in the Linux kernel Xen paravirtual network frontend, xen-netfront. handle_incoming_queue() copies the first RX slot from the backend, capped at RX_COPY_THRESHOLD, into the socket-buffer head and then calls eth_type_trans() without checking that at least an Ethernet header (ETH_HLEN) is present. If that first slot is shorter than ETH_HLEN and more slots follow, the guest BUG()s in __skb_pull(); if the whole packet is shorter than ETH_HLEN, eth_type_trans() reads the header past the end of the packet data. A Xen backend (typically dom0 or a driver domain) can therefore crash the Linux guest; this is not reachable by an unprivileged remote attacker on non-Xen hosts. No public proof of concept is known, the issue is not in CISA KEV, and exploitation in the wild is not reported. Do: Install a distribution kernel that includes the xen-netfront fix from XSA-522 / CVE-2026-98375 and reboot affected guests so the new driver is loaded. Until then, treat dom0 and any Xen network driver domain as trusted, because a compromised or malicious backend can crash the guest with malformed RX packets. The supplied data names no fixed version, so match the patch to your distro advisory rather than assuming a version number. |
Posted by Xen . org security team on Oct 09 Xen Security Advisory CVE-2026-98375 / XSA-522 Linux xen-netfront: backend can crash guest via malformed RX packets ISSUE DESCRIPTION ================= If a RX packet sent from the networking backend to the Linux xen-netfront driver is split into multiple slots and the first slot is shorter than an Ethernet header, a BUG() will crash the guest. This is a backend induced Denial of Service (DoS). IMPACT ====== A malicious network...
This source does not provide full text. Read it at seclists.org.