{"id":"DEBIAN-CVE-2022-49066","details":"In the Linux kernel, the following vulnerability has been resolved:  veth: Ensure eth header is in skb's linear part  After feeding a decapsulated packet to a veth device with act_mirred, skb_headlen() may be 0. But veth_xmit() calls __dev_forward_skb(), which expects at least ETH_HLEN byte of linear data (as __dev_forward_skb2() calls eth_type_trans(), which pulls ETH_HLEN bytes unconditionally).  Use pskb_may_pull() to ensure veth_xmit() respects this constraint.  kernel BUG at include/linux/skbuff.h:2328! RIP: 0010:eth_type_trans+0xcf/0x140 Call Trace:  \u003cIRQ\u003e  __dev_forward_skb2+0xe3/0x160  veth_xmit+0x6e/0x250 [veth]  dev_hard_start_xmit+0xc7/0x200  __dev_queue_xmit+0x47f/0x520  ? skb_ensure_writable+0x85/0xa0  ? skb_mpls_pop+0x98/0x1c0  tcf_mirred_act+0x442/0x47e [act_mirred]  tcf_action_exec+0x86/0x140  fl_classify+0x1d8/0x1e0 [cls_flower]  ? dma_pte_clear_level+0x129/0x1a0  ? dma_pte_clear_level+0x129/0x1a0  ? prb_fill_curr_block+0x2f/0xc0  ? skb_copy_bits+0x11a/0x220  __tcf_classify+0x58/0x110  tcf_classify_ingress+0x6b/0x140  __netif_receive_skb_core.constprop.0+0x47d/0xfd0  ? __iommu_dma_unmap_swiotlb+0x44/0x90  __netif_receive_skb_one_core+0x3d/0xa0  netif_receive_skb+0x116/0x170  be_process_rx+0x22f/0x330 [be2net]  be_poll+0x13c/0x370 [be2net]  __napi_poll+0x2a/0x170  net_rx_action+0x22f/0x2f0  __do_softirq+0xca/0x2a8  __irq_exit_rcu+0xc1/0xe0  common_interrupt+0x83/0xa0","modified":"2026-09-01T16:05:30.008992980Z","published":"2025-02-26T07:00:43.820Z","upstream":["CVE-2022-49066"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2022-49066"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.17.6-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-49066.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.17.6-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-49066.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.17.6-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-49066.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}