CVE-2026-80731

Summary

In the Linux kernel, the following vulnerability has been resolved:

net: remove CAP_SYS_RAWIO zero-padding in dev_validate_header

dev_validate_header() reads dev->hard_header_len directly when zero-padding short link layer headers for CAP_SYS_RAWIO holders:

if (capable(CAP_SYS_RAWIO)) {
    memset(ll_header + len, 0, dev->hard_header_len - len);
    return true;
}

Packet send paths call dev_validate_header() on skbs whose headroom was allocated from an earlier hard_header_len read. If the device is reconfigured so that dev->hard_header_len increases before validation, the memset writes past the reserved buffer, an out-of-bounds write.

This out-of-bounds write is masked in some SOCK_RAW paths today because the same concurrent increase can first make skb_push() exceed the reserved headroom and trigger skb_under_panic(). Remove the zero-padding branch before making those hard_header_len reads consistent, so the snapshot fixes do not turn a loud panic into a silent overwrite.

This path is only reached for variable length L2 protocols, where len < hard_header_len but len >= min_header_len. No remaining in-tree variable length L2 protocol implements header_ops->validate, and the CAP_SYS_RAWIO bypass that zero-pads and accepts short headers has no real value beyond allowing testing of intentionally malformed input.

Drop the CAP_SYS_RAWIO branch. The remaining reads of dev->hard_header_len in dev_validate_header() are comparisons only and have no memory safety impact.

Affected Software

VendorProductVersion RangeStatus
LinuxLinuxb5518429e70cd783b8ca52335456172c1a0589f6 < 53fd7f912c0877647d6a1e1877f5ea8535ee0b4aaffected
LinuxLinux2793a23aacbd754dbbb5cb75093deb7e4103bace < fa6d98dd925e72fc028b26a0cbbff9d2f0601ff6affected
LinuxLinux2793a23aacbd754dbbb5cb75093deb7e4103bace < 8fc9816404166a90ed8d544dc52482fafffb6d9faffected
LinuxLinux2793a23aacbd754dbbb5cb75093deb7e4103bace < b0f92a5731dc82556a9ae005cc35f71ab136307baffected
LinuxLinux2793a23aacbd754dbbb5cb75093deb7e4103bace < 99df6b7a713f96eda206680d100b76e15f9d9b69affected
LinuxLinux2793a23aacbd754dbbb5cb75093deb7e4103bace < 74e035f07f53feca09e2352e77fccb09cad5e208affected
LinuxLinux2793a23aacbd754dbbb5cb75093deb7e4103bace < dbb30dc943a93e083f1e531bfdc6779e57de40d0affected
LinuxLinux2793a23aacbd754dbbb5cb75093deb7e4103bace < fc902f52a02298c7432b2334c0c82a2885a1a8b6affected
LinuxLinux2793a23aacbd754dbbb5cb75093deb7e4103bace < 3b9a324e646d3657a8d9806dfbfe4f3e4066e882affected
LinuxLinuxf58a6c08ebdfa978178bbca78c2ba744a2665912affected
LinuxLinux1df16498dfd0d5a129bdf2982d9a08df73e8923daffected
LinuxLinux8b8d278aa4de9335682bbd4a3bb619af015c859eaffected
LinuxLinux6804052fa9d86e9a512c88b24a5debbfc1a490fcaffected
LinuxLinux3.2.80 < 3.2.81affected
LinuxLinux3.16.36 < 3.17affected
LinuxLinux4.1.28 < 4.2affected
LinuxLinux4.4.8 < 4.5affected
LinuxLinux4.5.2 < 4.6affected
LinuxLinux4.6affected
LinuxLinux0 < 4.6unaffected
LinuxLinux3.2.81 <= 3.2.*unaffected
LinuxLinux5.10.265 <= 5.10.*unaffected
LinuxLinux5.15.216 <= 5.15.*unaffected
LinuxLinux6.1.183 <= 6.1.*unaffected
LinuxLinux6.6.152 <= 6.6.*unaffected
LinuxLinux6.12.104 <= 6.12.*unaffected
LinuxLinux6.18.45 <= 6.18.*unaffected
LinuxLinux7.1.9 <= 7.1.*unaffected
LinuxLinux7.2 <= *unaffected

Weaknesses

References