Back to overview

CVE-2026-52985

Description
In the Linux kernel, the following vulnerability has been resolved: netdevsim: zero initialize struct iphdr in dummy sk_buff Syzbot reports a KMSAN uninit-value originating from nsim_dev_trap_skb_build, with the allocation also being performed in the same function. Fix this by calling skb_put_zero instead of skb_put to guarantee zero initialization of the whole IP header.

Metadata

CVE ID
CVE-2026-52985
State
PUBLISHED
Assigner
Linux
Reserved
2026-06-09 07:44 UTC
Published
2026-06-24 16:28 UTC
Last updated
2026-06-24 16:28 UTC
Vendor / Product
Linux / Linux
Sources
cve.org  ·  NVD

Severity & Metrics

No CVSS data available.

Affected products (2)
VendorProductPlatformVersions
Linux Linux da58f90f11f597520f226caff1d3cfc115abedc9 < 175556c049eaec14efde8c6475e763b7579b9de7, da58f90f11f597520f226caff1d3cfc115abedc9 < 6e2cfd0904976e701d7a76b86b694e72af230ab0, da58f90f11f597520f226caff1d3cfc115abedc9 < 1b7b6ae0e93b8d512e208b1378d74af052e4f4e7, da58f90f11f597520f226caff1d3cfc115abedc9 < 818f7673ed7f4a29d4b9cee8184c47d6e57162b4 …
Linux Linux 5.4, 0 < 5.4, 5.10.258 ≤ 5.10.*, 5.15.209 ≤ 5.15.* …
Back to overview