CVE-2026-45842

Source
https://cve.org/CVERecord?id=CVE-2026-45842
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-45842.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-45842
Downstream
AZL (1)
BELL (1)
DEBIAN (1)
ECHO (1)
openSUSE (2)
ROOT (5)
SUSE (11)
UBUNTU (1)
Related
Published
2026-05-27T09:24:42Z
Modified
2026-10-08T02:51:24Z
Summary
slip: reject VJ receive packets on instances with no rstate array
Details

In the Linux kernel, the following vulnerability has been resolved:

slip: reject VJ receive packets on instances with no rstate array

slhc_init() accepts rslots == 0 as a valid configuration, with the documented meaning of 'no receive compression'. In that case the allocation loop in slhc_init() is skipped, so comp->rstate stays NULL and comp->rslot_limit stays 0 (from the kzalloc of struct slcompress).

The receive helpers do not defend against that configuration. slhc_uncompress() dereferences comp->rstate[x] when the VJ header carries an explicit connection ID, and slhc_remember() later assigns cs = &comp->rstate[...] after only comparing the packet's slot number to comp->rslot_limit. Because rslot_limit is 0, slot 0 passes the range check, and the code dereferences a NULL rstate.

The configuration is reachable in-tree through PPP. PPPIOCSMAXCID stores its argument in a signed int, and (val >> 16) uses arithmetic shift. Passing 0xffff0000 therefore sign-extends to -1, so val2 + 1 is 0 and ppp_generic.c ends up calling slhc_init(0, 1). Because /dev/ppp open is gated by ns_capable(CAP_NET_ADMIN), the whole path is reachable from an unprivileged user namespace. Once the malformed VJ state is installed, any inbound VJ-compressed or VJ-uncompressed frame that selects slot 0 crashes the kernel in softirq context:

Oops: general protection fault, probably for non-canonical address 0xdffffc0000000000: 0000 [#1] SMP KASAN NOPTI KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007] RIP: 0010:slhc_uncompress (drivers/net/slip/slhc.c:519) Call Trace: ppp_receive_nonmp_frame (drivers/net/ppp/ppp_generic.c:2466) ppp_input (drivers/net/ppp/ppp_generic.c:2359) ppp_async_process (drivers/net/ppp/ppp_async.c:492) tasklet_action_common (kernel/softirq.c:926) handle_softirqs (kernel/softirq.c:623) run_ksoftirqd (kernel/softirq.c:1055) smpboot_thread_fn (kernel/smpboot.c:160) kthread (kernel/kthread.c:436) ret_from_fork (arch/x86/kernel/process.c:164)

Reject the receive side on such instances instead of touching rstate. slhc_uncompress() falls through to its existing 'bad' label, which bumps sls_i_error and enters the toss state. slhc_remember() mirrors that with an explicit sls_i_error increment followed by slhc_toss(); the sls_i_runt counter is not used here because a missing rstate is an internal configuration state, not a runt packet.

The transmit path is unaffected: the only in-tree caller that picks rslots from userspace (ppp_generic.c) still supplies tslots >= 1, and slip.c always calls slhc_init(16, 16), so comp->tstate remains valid and slhc_compress() continues to work.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45842.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
4ab42d78e37a294ac7bc56901d563c642e03c4ae
Fixed
3d71c961febddd855d3ae9a519eeb96c8023f430
Fixed
72304fec672e8aac9ee7b9c475db96b37cca8d8d
Fixed
4aa9eca6fda2919027dfd7a7cc69334982d89586
Fixed
c6980e8b1a86288167f34966fa5219031999b6f1
Fixed
de42f86e2cf5028a97e74c25869d1a962b13c301
Fixed
9e1ff0eead073c4f46d874ad2526b7dda5465faf
Fixed
7b0d9e878ec2b21d99ae8051b3dda59cdb66c152
Fixed
e76607442d5b73e1ba6768f501ef815bb58c2c0e
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
2.6.32.70
Fixed
2.6.33
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
3.2.75
Fixed
3.3
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
3.4.111
Fixed
3.5
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
3.10.96
Fixed
3.11
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
3.12.53
Fixed
3.13
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
3.14.60
Fixed
3.15
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
3.18.27
Fixed
3.19
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
4.1.17
Fixed
4.2
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
4.3.5
Fixed
4.4
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
42fc512469e78939c1e419d3310c47de55bdcbb8
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
df085f1cb3acd3d75408ff94f366983873bce7d2
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
a1c3860d3c5fc62bd35f089bcb03f18a37242de9
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
f82699de104eaf8a7ffc2849a566a94818dd8a3c
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
354b254af5c1350de9586af75fe5a821b35bfb33
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
5148857f5d4c812cc918cf4627f7880521e987eb
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
82185755d90c8047c6f4b589c39998ff3d4ca3ad
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
a50a93cc99286dc444c7e5ccc7dfb9d58c2d346d
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
6b4fa561e26526c62636414d267342c945084f44

Affected versions

v2.*
v2.6.32.70
v2.6.32.71
v3.*
v3.10.100
v3.10.101
v3.10.102
v3.10.103
v3.10.104
v3.10.105
v3.10.106
v3.10.107
v3.10.108
v3.10.96
v3.10.97
v3.10.98
v3.10.99
v3.12.53
v3.12.54
v3.12.55
v3.12.56
v3.12.57
v3.12.58
v3.12.59
v3.12.60
v3.12.61
v3.12.62
v3.12.63
v3.12.64
v3.12.65
v3.12.66
v3.12.67
v3.12.68
v3.12.69
v3.12.70
v3.12.71
v3.12.72
v3.12.73
v3.12.74
v3.14.60
v3.14.61
v3.14.62
v3.14.63
v3.14.64
v3.14.65
v3.14.66
v3.14.67
v3.14.68
v3.14.69
v3.14.70
v3.14.71
v3.14.72
v3.14.73
v3.14.74
v3.14.75
v3.14.76
v3.14.77
v3.14.78
v3.14.79
v3.18.100
v3.18.101
v3.18.102
v3.18.103
v3.18.104
v3.18.105
v3.18.106
v3.18.107
v3.18.108
v3.18.109
v3.18.110
v3.18.111
v3.18.112
v3.18.113
v3.18.114
v3.18.115
v3.18.116
v3.18.117
v3.18.118
v3.18.119
v3.18.120
v3.18.121
v3.18.122
v3.18.123
v3.18.124
v3.18.125
v3.18.126
v3.18.127
v3.18.128
v3.18.129
v3.18.130
v3.18.131
v3.18.132
v3.18.133
v3.18.134
v3.18.135
v3.18.136
v3.18.137
v3.18.138
v3.18.139
v3.18.140
v3.18.27
v3.18.28
v3.18.29
v3.18.30
v3.18.31
v3.18.32
v3.18.33
v3.18.34
v3.18.35
v3.18.36
v3.18.37
v3.18.38
v3.18.39
v3.18.40
v3.18.41
v3.18.42
v3.18.43
v3.18.44
v3.18.45
v3.18.46
v3.18.47
v3.18.48
v3.18.49
v3.18.50
v3.18.51
v3.18.52
v3.18.53
v3.18.54
v3.18.55
v3.18.56
v3.18.57
v3.18.58
v3.18.59
v3.18.60
v3.18.61
v3.18.62
v3.18.63
v3.18.64
v3.18.65
v3.18.66
v3.18.67
v3.18.68
v3.18.69
v3.18.70
v3.18.71
v3.18.72
v3.18.73
v3.18.74
v3.18.75
v3.18.76
v3.18.77
v3.18.78
v3.18.79
v3.18.80
v3.18.81
v3.18.82
v3.18.83
v3.18.84
v3.18.85
v3.18.86
v3.18.87
v3.18.88
v3.18.89
v3.18.90
v3.18.91
v3.18.92
v3.18.93
v3.18.94
v3.18.95
v3.18.96
v3.18.97
v3.18.98
v3.18.99
v3.2.100
v3.2.101
v3.2.102
v3.2.75
v3.2.76
v3.2.77
v3.2.78
v3.2.79
v3.2.80
v3.2.81
v3.2.82
v3.2.83
v3.2.84
v3.2.85
v3.2.86
v3.2.87
v3.2.88
v3.2.89
v3.2.90
v3.2.91
v3.2.92
v3.2.93
v3.2.94
v3.2.95
v3.2.96
v3.2.97
v3.2.98
v3.2.99
v3.4.111
v3.4.112
v3.4.113
v4.*
v4.1.17
v4.1.18
v4.1.19
v4.1.20
v4.1.21
v4.1.22
v4.1.23
v4.1.24
v4.1.25
v4.1.26
v4.1.27
v4.1.28
v4.1.29
v4.1.30
v4.1.31
v4.1.32
v4.1.33
v4.1.34
v4.1.35
v4.1.36
v4.1.37
v4.1.38
v4.1.39
v4.1.40
v4.1.41
v4.1.42
v4.1.43
v4.1.44
v4.1.45
v4.1.46
v4.1.47
v4.1.48
v4.1.49
v4.1.50
v4.1.51
v4.1.52
v4.3.5
v4.3.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-45842.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.4.0
Fixed
5.10.258
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.209
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.175
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.141
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.91
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.33
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.0.10

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-45842.json"