---
id: CVE-2026-52985
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  netdevsim: zero initialize struct iphdr in dummy sk_buff

  Syzbot reports a KMSAN uninit-value originating from
  nsim_dev_trap_skb_build, with the allocation also
  being p…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  netdevsim: zero initialize struct iphdr in dummy sk_buff

  Syzbot reports a KMSAN uninit-value originating from
  nsim_dev_trap_skb_build, with the allocation also
  being p…
severity: none
published: '2026-06-24'
updated: '2026-07-10'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-52985'
references:
  - url: 'https://git.kernel.org/stable/c/175556c049eaec14efde8c6475e763b7579b9de7'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/1b7b6ae0e93b8d512e208b1378d74af052e4f4e7'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/35eaa6d8d6c2ee65e96f507add856e0eacf24591'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/6e2cfd0904976e701d7a76b86b694e72af230ab0'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/750d0091bebf44975421268d37484ef87060d263'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/818f7673ed7f4a29d4b9cee8184c47d6e57162b4'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/978ca6ff789f1f19c03288ac20cc1f4774e88490'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/bc6002865e8c4fcf9e94975f7cf023448d8764e2'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
epss: 0.00162
epssPercentile: 0.04774
ingestedAt: '2026-07-11T13:13:25.504Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

netdevsim: zero initialize struct iphdr in dummy sk_buff

Syzbot reports a KMSAN uninit-value originating from
nsim_dev_trap_skb_build, with the allocation also
being performed in the same function.

Fix this by calling skb_put_zero instead of skb_put to
guarantee zero initialization of the whole IP header.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
