"value":"En el kernel de Linux, se resolvi\u00f3 la siguiente vulnerabilidad: geneve: aseg\u00farese de extraer el encabezado interno en geneve_rx() syzbot desencaden\u00f3 un error en geneve_rx() [1] El problema es similar al que solucion\u00e9 en la confirmaci\u00f3n 8d975c15c0cd (\"ip6_tunnel: aseg\u00farese de extraer el encabezado interno en __ip6_tnl_rcv()\").Tenemosqueguardarskb->network_headerenunavariabletemporalparapodervolveracalcularelpunteronetwork_headerdespu\u00e9sdeunallamadaapskb_inet_may_pull().pskb_inet_may_pull()seaseguradequelosencabezadosnecesariosest\u00e9nenskb->head.[1]ERROR:KMSAN:valoruninitenIP_ECN_decapsulateinclude/net/inet_ecn.h:302[enl\u00ednea]ERROR:KMSAN:valoruninitengeneve_rxdrivers/net/geneve.c:279[enl\u00ednea]ERROR:KMSAN:uninit-valorengeneve_udp_encap_recv+0x36f9/0x3c10drivers/net/geneve.c:391IP_ECN_decapsulateinclude/net/inet_ecn.h:302[enl\u00ednea]geneve_rxdrivers/net/geneve.c:279[enl\u00ednea]geneve_udp_encap_recv+0x36f9/0x3c10drivers/net/geneve.c:391udp_queue_rcv_one_skb+0x1d39/0x1f20net/ipv4/udp.c:2108udp_queue_rcv_skb+0x6ae/0x6e0net/ipv4/udp.c:2186udp_unicast_rcv_skb+0x184/0x4b0net/ipv4/udp.c:2346__udp4_lib_rcv+0x1c6b/0x3010net/ipv4/udp.c:2422udp_rcv+0x7d/0xa0net/ipv4/udp.c:2604ip_protocol_deliver_rcu+0x264/0x1300net/ipv4/ip_input.c:205ip_local_deliver_finish+0x2b8/0x440net/ipv4/ip_input.c:233NF_HOOKinclude/linux/netfilter.h:314[enl\u00ednea]ip_local_deliver+0x21f/0x490net/ipv4/ip_input.c:254dst_inputinclude/net/dst.h:461[enl\u00ednea]ip_rcv_finishnet/ipv4/ip_input.c:449[enl\u00ednea]NF_HOOKinclude/linux/netfilter.h:314[enl\u00ednea]ip_rcv+0x46f/0x760net/ipv4/ip_input.c:569__netif_receive_skb_one_corenet/core/dev.c:5534[enl\u00ednea]__netif_receive_skb+0x1a6/0x5a0net/core/dev.c:5648Process_backlog+0x480/0x8b0net/core/dev.c:5976__napi_poll+0xe3/0x980net/core/dev.c:6576napi_pollnet/core/dev.c:6645[enl\u00ednea]net_rx_action+0x8b8/0x1870net/core/dev.c:6778__do_softirq+0x1b7/0x7c5kernel/softirq.c:553do_softirq+0x9a/0xf0kernel/softirq.c:454__local_bh_enable_ip+0x9b/0xa0kernel/softirq.c:381local_bh_enableinclude/linux/bottom_half.h:33[enl\u00ednea]rcu_read_unlock_bhinclude/linux/rcupdate.h:820[enl\u00ednea]__dev_queue_xmit+0x2768/0x51c0net/core/dev.c:4378dev_queue_xmitinclude/linux/netdevice.h:3171[enl\u00ednea]paquete_xmit+0x9c/0x6b0net/packet/af_packet.c:276paquete_sndnet/packet/af_packet.c:3081[enl\u00ednea]paquete_sendmsg+0x8aef/0x9f10net/packet/af_packet.c:3113sock_sendmsg_nosecnet/socket.c:730[enl\u00ednea]__sock_sendmsgnet/socket.c:745[enl\u00ednea]__sys_sendto+0x735/0xa10net/socket.c:2191__do_sys_sendtonet/socket.c:2203[enl\u00ednea]__se_sys_sendtonet/socket.c:2199[enl\u00ednea]__x64_sys_sendto+0x125/0x1c0net/socket.c:2199do_syscall_x64arch/x86/entry/common.c:52[enl\u00ednea]do_syscall_64+0xcf/0x1e0arch/x86/entry/common.c:83Entry_SYSCALL_64_after_hwframe+0x63/0x6bUninitsecre\u00f3en:slab_post_alloc_hookmm/slub.c:3819[enl\u00ednea]slab_alloc_nodemm/slub.c:3860[enl\u00ednea]kmem_cache_alloc_node+0x5cb/0xbc0mm/slub.c:3903kmalloc_reserve+0x13d/0x4a0net/core/skbuff.c:560__alloc_skb+0x352/0x790net/core/skbuff.c:651alloc_skbinclude/linux/skbuff.h:1296[enl\u00ednea]alloc_skb_with_frags+0xc8/0xbd0net/core/skbuff.c:6394sock_alloc_send_pskb+0xa80/0xbf0net/core/sock.c:2783paquete_alloc_skbnet/packet/af_packet.c:2930[enl\u00ednea]paquete_sndnet/packet/af_packet.c:3024[enl\u00ednea]paquete_sendmsg+0x70c2/0x9f10net/packet/af_packet.c:3113sock_sendmsg_nosecnet/socket.c:730[enl\u00ednea]__sock_sendmsgnet/socket.c:745[enl\u00ednea]__sys_sendto+0x735/0xa10net/socket.c:2191__do_sys_sendtonet/socket.c:2203[enl\u00ednea]__se_sys_sendtonet/socket.c:2199[enl\u00ednea]__x64_sys_sendto+0x125/0x1c0net/socket.c:2199do_syscall_x64arch/x86/entry/common.c:52[enl\u00ednea]do_syscall_64+0xcf/0x1e0arch/x86/entry/common.c:83Entry_SYSCALL_64_after_hwfr