---
id: CVE-2026-97612
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  net: mpls: clear inner_protocol when the last label is popped

  skb_mpls_push() records the pre-encapsulation network header once, gated
  on !skb->inner_protocol
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  net: mpls: clear inner_protocol when the last label is popped

  skb_mpls_push() records the pre-encapsulation network header once, gated
  on !skb->inner_protocol. skb_mpl…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 48d2ab609b6bbecb7698487c8579bc40de9d6dfa <
    011e17b5cae19b9f6a150923275e41c278de64f0
  - >-
    Linux >= 48d2ab609b6bbecb7698487c8579bc40de9d6dfa <
    da8c3a7f5d3137fec4ff60a6248f5f6d66b6a63e
  - >-
    Linux >= 48d2ab609b6bbecb7698487c8579bc40de9d6dfa <
    b39120523475d6b436be7f6cb27d48064148a327
  - >-
    Linux >= 48d2ab609b6bbecb7698487c8579bc40de9d6dfa <
    78a86d75a70e1e227711c72865c59b1422d0a5ae
  - Linux 4.9
published: '2026-09-25'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T15:18:01.500'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-97612'
references:
  - url: 'https://git.kernel.org/stable/c/011e17b5cae19b9f6a150923275e41c278de64f0'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/78a86d75a70e1e227711c72865c59b1422d0a5ae'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/b39120523475d6b436be7f6cb27d48064148a327'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/da8c3a7f5d3137fec4ff60a6248f5f6d66b6a63e'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-25T11:06:38.899Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

net: mpls: clear inner_protocol when the last label is popped

skb_mpls_push() records the pre-encapsulation network header once, gated
on !skb->inner_protocol. skb_mpls_pop() never clears that record, so it
outlives the encapsulation it describes.

Open vSwitch can then re-push MPLS onto a packet whose
inner_network_header still points at the older, deeper offset: push a
label, pop every label, recirculate (ovs_flow_key_update() re-derives
key->eth.type and resets network_header, but leaves inner_*), then push
again. ovs_fragment() trusts the record:

	skb->network_header = skb->inner_network_header;

so skb_network_offset() goes negative. The bound check is signed:

	if (skb_network_offset(skb) > MAX_L2_LEN)

a negative offset passes it, and prepare_frag() widens the value:

	unsigned int hlen = skb_network_offset(skb);
	memcpy(&data->l2_data, skb->data, hlen);

which is a ~4GiB memcpy out of a 30-byte per-CPU buffer.

Reproduced on v7.3-rc1. RDX is the truncated length, (unsigned int)(-8):

  BUG: unable to handle page fault for address: ffffe8ffffc16000
  #PF: supervisor write access in kernel mode
  Oops: 0002 [#1] SMP KASAN NOPTI
  RIP: 0010:memcpy+0x8/0x20
  RDX: 00000000fffffff8 RSI: ffff888105d732db RDI: ffffe8ffffc16000
   prepare_frag+0x3df/0x4e0
   ovs_fragment+0x589/0x7e0
   do_output+0x4ce/0x5e0
   do_execute_actions+0x55d2/0x7b30
   ovs_execute_actions+0xea/0x450

Same root-cause shape as commit 975b5b067f52 ("ipv6: sr: restore network
header before routing and forwarding"): a stale network header offset
reaching a consumer that widens it. Here it originates in the MPLS
push/pop path.

Clear inner_protocol once the packet is no longer MPLS, so a later push
re-records the current header. net/sched/act_mpls.c is the only other
skb_mpls_pop() caller and gets the same fix; sch_frag.c saves and
restores inner_protocol around fragmentation in the same way OVS does.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
