Signed to Unsigned Conversion Error in Linux kernel - CVE-2026-97612
Published: September 28, 2026
Vulnerability details
The vulnerability allows a local user to cause memory corruption.
The vulnerability exists due to stale inner protocol state in skb_mpls_pop() when Open vSwitch re-pushes MPLS after all labels have been popped and the packet has been recirculated. A local user can trigger MPLS label push, pop, recirculation, and a subsequent label push to cause memory corruption.