CVE-2026-74668

Summary

In the Linux kernel, the following vulnerability has been resolved:

packet: use consistent hard_header_len in TX_RING send path

tpacket_snd() reads dev->hard_header_len independently for skb allocation and header construction in tpacket_fill_skb(). Concurrent netdevice reconfiguration can therefore make the reserved headroom smaller than the amount later pushed, or make copylen - hard_header_len negative.

Snapshot hard_header_len once before processing ring frames and use it for the frame limit, headroom allocation, copy length, and skb construction. Pass the snapshot to tpacket_fill_skb().

The separate SOCK_DGRAM consistency problem between hard_header_len and header_ops->create is not addressed here.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux69e3c75f4d541a6eb151b3ef91f34033cb3ad6e1 < d85d2fd54e901637c81d847811e03c662aee13cdaffected
LinuxLinux69e3c75f4d541a6eb151b3ef91f34033cb3ad6e1 < 016763e829cac37b3234eace86fd0a4c560de4a7affected
LinuxLinux69e3c75f4d541a6eb151b3ef91f34033cb3ad6e1 < 27e068d1b35dbec10a3cf268887c94407be4badcaffected
LinuxLinux69e3c75f4d541a6eb151b3ef91f34033cb3ad6e1 < d48ea5c9c4c34dc0df621f0e39ed3a16b644621aaffected
LinuxLinux69e3c75f4d541a6eb151b3ef91f34033cb3ad6e1 < 21b5953e7494c16a42e6cd8cf110e18d13ae4a6baffected
LinuxLinux2.6.31affected
LinuxLinux0 < 2.6.31unaffected
LinuxLinux6.6.152 <= 6.6.*unaffected
LinuxLinux6.12.104 <= 6.12.*unaffected
LinuxLinux6.18.45 <= 6.18.*unaffected
LinuxLinux7.1.9 <= 7.1.*unaffected
LinuxLinux7.2 <= *unaffected

Weaknesses

References