CVE-2026-74667: net/packet: reset the MAC header on the packet-socket transmit path
Greg Kroah-Hartman <[email protected]>
| Newsgroups | org.kernel.vger.linux-cve-announce |
|---|---|
| Message-ID | <2026082229-CVE-2026-74667-8fdf@gregkh> |
From: Greg Kroah-Hartman <[email protected]> Description =========== In the Linux kernel, the following vulnerability has been resolved: net/packet: reset the MAC header on the packet-socket transmit path packet_parse_headers() resets the MAC header only for a SOCK_RAW frame whose socket did not bind a protocol. A protocol-bound SOCK_RAW socket, any SOCK_DGRAM frame, and the legacy SOCK_PACKET path therefore leave skb->mac_header unset here. For frames sent via __dev_queue_xmit() this is harmless: it resets the MAC header unconditionally. But the packet-socket PACKET_QDISC_BYPASS path uses dev_direct_xmit(), which does not, so the frame reaches ndo_start_xmit() with the MAC header unset. A driver that reads eth_hdr(skb) on transmit then dereferences skb->head + (u16)~0, an out-of-bounds access ~64 KiB past the head -- the same class fixed for one consumer in commit f5089008f90c ("macsec: do not read an unset MAC header in macsec_encrypt()"). packet_parse_headers() runs only on the transmit path, where skb->data points at the start of the L2 header for every packet-socket type regardless of its length: SOCK_RAW and SOCK_PACKET carry a user-supplied header and SOCK_DGRAM has one built by dev_hard_header(). Reset the MAC header unconditionally, mirroring __dev_queue_xmit(), so the frame is anchored on the bypass path too. Found by 0sec (https://0sec.ai) using automated source analysis; verified against source and matched to the macsec KASAN report in f5089008f90c. Compile-tested. The Linux kernel CVE team has assigned CVE-2026-74667 to this issue. Affected and fixed versions =========================== Issue introduced in 5.1 with commit 75c65772c3d18447d62d3aca5f91b06c16cc25e4 and fixed in 5.10.265 with commit 1e43a1d66615f411d427f9df1f46dd049d9e3681 Issue introduced in 5.1 with commit 75c65772c3d18447d62d3aca5f91b06c16cc25e4 and fixed in 5.15.216 with commit 4057853a91fb796c4f47c7d1baf1aa085394148e Issue introduced in 5.1 with commit 75c65772c3d18447d62d3aca5f91b06c16cc25e4 and fixed in 6.1.183 with commit 2610ed4e86a4590234a9d70518c469751c5af231 Issue introduced in 5.1 with commit 75c65772c3d18447d62d3aca5f91b06c16cc25e4 and fixed in 6.6.152 with commit b47ba8fe6e1d2df8c92048de5afafd059447dc30 Issue introduced in 5.1 with commit 75c65772c3d18447d62d3aca5f91b06c16cc25e4 and fixed in 6.12.104 with commit 284f3e7a3f1a743fdf89e304fd1f19d5ffcff46d Issue introduced in 5.1 with commit 75c65772c3d18447d62d3aca5f91b06c16cc25e4 and fixed in 6.18.45 with commit 971aa7d99242bbf09513e27b7a243f0b29ff23ae Issue introduced in 5.1 with commit 75c65772c3d18447d62d3aca5f91b06c16cc25e4 and fixed in 7.1.9 with commit fdd4d7d52358a58e351dd9d82530c04eba8ccd7a Issue introduced in 5.1 with commit 75c65772c3d18447d62d3aca5f91b06c16cc25e4 and fixed in 7.2 with commit c2707480cfbf19c7619acc9c089d17f20869821f Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-74667 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: net/packet/af_packet.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/1e43a1d66615f411d427f9df1f46dd049d9e3681 https://git.kernel.org/stable/c/4057853a91fb796c4f47c7d1baf1aa085394148e https://git.kernel.org/stable/c/2610ed4e86a4590234a9d70518c469751c5af231 https://git.kernel.org/stable/c/b47ba8fe6e1d2df8c92048de5afafd059447dc30 https://git.kernel.org/stable/c/284f3e7a3f1a743fdf89e304fd1f19d5ffcff46d https://git.kernel.org/stable/c/971aa7d99242bbf09513e27b7a243f0b29ff23ae https://git.kernel.org/stable/c/fdd4d7d52358a58e351dd9d82530c04eba8ccd7a https://git.kernel.org/stable/c/c2707480cfbf19c7619acc9c089d17f20869821f