Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: net/sched: Fix ethx:ingress -> ethy:egress -> ethx:ingress mirred loop When mirred redirects to ingress (from either ingress or egress) the loop state from sched_mirred_dev array dev is lost because of 1) the packet deferral into the backlog and 2) the fact the sched_mirred_dev array is cleared. In such cases, if there was a loop we won't discover it. Here's a simple test to reproduce: ip a add dev port0 10.10.10.11/24 tc qdisc add dev port0 clsact tc filter add dev port0 egress protocol ip \ prio 10 matchall action mirred ingress redirect dev port1 tc qdisc add dev port1 clsact tc filter add dev port1 ingress protocol ip \ prio 10 matchall action mirred egress redirect dev port0 ping -c 1 -W0.01 10.10.10.10
References
- https://git.kernel.org/stable/c/45ac526a0d5733c3695946bd84ec57f24d8f5e66
- https://git.kernel.org/stable/c/66f4607fe788fc7d81bce0e2f7b3726ed2f71284
- https://git.kernel.org/stable/c/db875221ab08d213a83bf30196ae8b64d55a3403
FAQ
What is CVE-2026-63982?
CVE-2026-63982 is a documented vulnerability. In the Linux kernel, the following vulnerability has been resolved: net/sched: Fix ethx:ingress -> ethy:egress -> ethx:ingress mirred loop When mirred redirects to ingress (from either ingress or eg...
How severe is CVE-2026-63982?
CVSS scoring is not yet available for CVE-2026-63982. Check NVD for updates.
Is there a patch for CVE-2026-63982?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.