CVE-2026-63982
Description
In the Linux kernel, the following vulnerability has been resolved:
net/sched: Fix ethx:ingress -> ethy:egress -> ethx:ingress mirred loop
When mirred redirects to ingress (from either ingress or egress) the loop
state from sched_mirred_dev array dev is lost because of 1) the packet
deferral into the backlog and 2) the fact the sched_mirred_dev array is
cleared. In such cases, if there was a loop we won't discover it.
Here's a simple test to reproduce:
ip a add dev port0 10.10.10.11/24
tc qdisc add dev port0 clsact
tc filter add dev port0 egress protocol ip \
prio 10 matchall action mirred ingress redirect dev port1
tc qdisc add dev port1 clsact
tc filter add dev port1 ingress protocol ip \
prio 10 matchall action mirred egress redirect dev port0
ping -c 1 -W0.01 10.10.10.10
Metadata
Severity & Metrics
No CVSS data available.
Affected products (2)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| Linux | Linux | — | 906736728cea480a85803c67fafb1b0e78491922 < 66f4607fe788fc7d81bce0e2f7b3726ed2f71284, fe946a751d9b52b7c45ca34899723b314b79b249 < 45ac526a0d5733c3695946bd84ec57f24d8f5e66, fe946a751d9b52b7c45ca34899723b314b79b249 < db875221ab08d213a83bf30196ae8b64d55a3403 |
| Linux | Linux | — | 6.19, 0 < 6.19, 7.0.12 ≤ 7.0.*, 7.1 ≤ * |
References (3)