---
id: CVE-2026-98375
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  xen/netfront: drop RX packets with a short Ethernet header

  handle_incoming_queue() pulls pull_to bytes into the head before
  calling eth_type_trans()
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  xen/netfront: drop RX packets with a short Ethernet header

  handle_incoming_queue() pulls pull_to bytes into the head before
  calling eth_type_trans().  pull_to is the l…
severity: none
published: '2026-10-09'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T08:16:55.807'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-98375'
references:
  - url: 'https://git.kernel.org/stable/c/089e58805c452e52179482b1025a8e309a57f801'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
ingestedAt: '2026-10-09T08:29:41.346Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

xen/netfront: drop RX packets with a short Ethernet header

handle_incoming_queue() pulls pull_to bytes into the head before
calling eth_type_trans().  pull_to is the length of the first RX slot,
capped at RX_COPY_THRESHOLD, and that length comes from the backend.
Nothing checks it against ETH_HLEN.

If the first slot is shorter than ETH_HLEN and more slots follow, the
head ends up shorter than an Ethernet header while skb->len is longer,
and eth_type_trans() BUG()s in __skb_pull().  If the whole packet is
shorter than ETH_HLEN, eth_type_trans() reads the header past the end
of the data instead.

Pull at least ETH_HLEN, and drop the packet if that fails, which also
drops packets too short to hold an Ethernet header.  This also checks
the return value of the pull, which was ignored.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
