{
  "schema_version": "1.6.1",
  "id": "RPI-CVE-2023-54114",
  "modified": "2026-10-07T17:22:01Z",
  "upstream": [
    "CVE-2023-54114"
  ],
  "published": "2025-12-24T13:11:50Z",
  "summary": "net: nsh: Use correct mac_offset to unwind gso skb in nsh_gso_segment()",
  "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: nsh: Use correct mac_offset to unwind gso skb in nsh_gso_segment()\n\nAs the call trace shows, skb_panic was caused by wrong skb->mac_header\nin nsh_gso_segment():\n\ninvalid opcode: 0000 [#1] PREEMPT SMP KASAN PTI\nCPU: 3 PID: 2737 Comm: syz Not tainted 6.3.0-next-20230505 #1\nRIP: 0010:skb_panic+0xda/0xe0\ncall Trace:\n skb_push+0x91/0xa0\n nsh_gso_segment+0x4f3/0x570\n skb_mac_gso_segment+0x19e/0x270\n __skb_gso_segment+0x1e8/0x3c0\n validate_xmit_skb+0x452/0x890\n validate_xmit_skb_list+0x99/0xd0\n sch_direct_xmit+0x294/0x7c0\n __dev_queue_xmit+0x16f0/0x1d70\n packet_xmit+0x185/0x210\n packet_snd+0xc15/0x1170\n packet_sendmsg+0x7b/0xa0\n sock_sendmsg+0x14f/0x160\n\nThe root cause is:\nnsh_gso_segment() use skb->network_header - nhoff to reset mac_header\nin skb_gso_error_unwind() if inner-layer protocol gso fails.\nHowever, skb->network_header may be reset by inner-layer protocol\ngso function e.g. mpls_gso_segment. skb->mac_header reset by the\ninaccurate network_header will be larger than skb headroom.\n\nnsh_gso_segment\n    nhoff = skb->network_header - skb->mac_header;\n    __skb_pull(skb,nsh_len)\n    skb_mac_gso_segment\n        mpls_gso_segment\n            skb_reset_network_header(skb);//skb->network_header+=nsh_len\n            return -EINVAL;\n    skb_gso_error_unwind\n        skb_push(skb, nsh_len);\n        skb->mac_header = skb->network_header - nhoff;\n        // skb->mac_header > skb->headroom, cause skb_push panic\n\nUse correct mac_offset to restore mac_header and get rid of nhoff.",
  "affected": [
    {
      "package": {
        "ecosystem": "Raspberry Pi OS:12",
        "name": "linux"
      },
      "versions": [
        "1:6.1.21-1+rpt1"
      ],
      "ecosystem_specific": {
        "binaries": [
          {
            "binary_name": "linux-image-6.1.0-rpi1-rpi-v6",
            "binary_version": "1:6.1.21-1+rpt1"
          },
          {
            "binary_name": "linux-image-6.1.0-rpi1-rpi-v7",
            "binary_version": "1:6.1.21-1+rpt1"
          },
          {
            "binary_name": "linux-image-6.1.0-rpi1-rpi-v7l",
            "binary_version": "1:6.1.21-1+rpt1"
          },
          {
            "binary_name": "linux-image-6.1.0-rpi1-rpi-v8",
            "binary_version": "1:6.1.21-1+rpt1"
          }
        ]
      },
      "database_specific": {
        "per_version": {
          "1:6.1.21-1+rpt1": {
            "linux_commit": "0afb5e98488aed7017b9bf321b575d0177feb7ed",
            "upstream_version": "6.1.21",
            "assessment": "commit ancestry (strak rule)",
            "upstream_fixed": "6.1.30"
          }
        }
      }
    }
  ],
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-54114"
    },
    {
      "type": "FIX",
      "url": "https://git.kernel.org/stable/c/2f88c8d38ecf5ed0273f99a067246899ba499eb2"
    },
    {
      "type": "FIX",
      "url": "https://git.kernel.org/stable/c/d2309e0cb27b6871b273fbc1725e93be62570d86"
    },
    {
      "type": "FIX",
      "url": "https://git.kernel.org/stable/c/435855b0831b351cb72cb38369ee33122ce9574c"
    },
    {
      "type": "FIX",
      "url": "https://git.kernel.org/stable/c/02b20e0bc0c2628539e9e518dc342787c3332de2"
    },
    {
      "type": "FIX",
      "url": "https://git.kernel.org/stable/c/cdd8160dcda1fed2028a5f96575a84afc23aff7d"
    },
    {
      "type": "FIX",
      "url": "https://git.kernel.org/stable/c/6fbedf987b6b8ed54a50e2205d998eb2c8be72f9"
    },
    {
      "type": "FIX",
      "url": "https://git.kernel.org/stable/c/cb38e62922aa3991793344b5a5870e7291c74a44"
    },
    {
      "type": "FIX",
      "url": "https://git.kernel.org/stable/c/c83b49383b595be50647f0c764a48c78b5f3c4f8"
    }
  ],
  "database_specific": {
    "source": "https://git.kernel.org/pub/scm/linux/security/vulns.git",
    "upstream_modified": "2026-05-12T04:54:46Z"
  }
}
