CVE-2026-74582

Unknown

Last modified

CVE-2026-74582 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: packet: use consistent hard_header_len in non-ring send paths packet_snd() reads dev->hard_header_len multiple times while allocating and constructing an skb. Device reconfiguration can change this value concurrently, for example through bonding device type changes. For SOCK_RAW, packet_snd() can save a larger value in reserve and later allocate headroom using a smaller value.

Description

In the Linux kernel, the following vulnerability has been resolved: packet: use consistent hard_header_len in non-ring send paths packet_snd() reads dev->hard_header_len multiple times while allocating and constructing an skb. Device reconfiguration can change this value concurrently, for example through bonding device type changes. For SOCK_RAW, packet_snd() can save a larger value in reserve and later allocate headroom using a smaller value. Moving skb->data back by reserve then places it before skb->head, and the following copy from userspace can attempt an out-of-bounds write. packet_sendmsg_spkt() has the same issue because it calculates its reservation and header offset from separate reads before dropping the RCU read lock to allocate the skb. Add LL_RESERVED_SPACE_EX() for callers that already saved a header length. Read hard_header_len once in packet_snd() and use it for allocation and construction. In packet_sendmsg_spkt(), preserve the allocation-time value through the device lookup retry. The separate SOCK_DGRAM consistency problem between hard_header_len and header_ops->create is not addressed here.

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= b84bbaf7a6c8cca24f8acf25a2c8e46913a947ba, < 91f041451f967cd87ed722a8f43c0b767a64f1a0; >= b84bbaf7a6c8cca24f8acf25a2c8e46913a947ba, < 9052756290962ffb9a661bcf319e92dedaaedfed; >= b84bbaf7a6c8cca24f8acf25a2c8e46913a947ba, < 5bb10753d428aadfc356a2bfe9acea09c82a62ec; >= b84bbaf7a6c8cca24f8acf25a2c8e46913a947ba, < b06b6fce6d7deaf7238e09b48ce3b1125ff41acd; >= b84bbaf7a6c8cca24f8acf25a2c8e46913a947ba, < 03390aa32e669cc4ecd7d34108e2e1afc13d689d; d9fb8cc230b2a4757e9fe4f81468f81212d4deaa; 6190cce26e40bf71c4d375b21eea74bb07b6a0f3; 01a658c1b9d4b5393c38d5a92d9112ab1425382a; 8809ae6747e760e6f1d2453ceb08c9bcc4939766; >= 4.4.133, < 4.5; >= 4.9.103, < 4.10; >= 4.14.44, < 4.15; >= 4.16.12, < 4.17
LinuxLinux4.17

References

Timeline

Published
Last Modified
Status
Received

Frequently Asked Questions

What is CVE-2026-74582?
In the Linux kernel, the following vulnerability has been resolved: packet: use consistent hard_header_len in non-ring send paths packet_snd() reads dev->hard_header_len multiple times while allocating and constructing an skb. Device reconfiguration can change this value concurrently, for example through bonding device type changes. For SOCK_RAW, packet_snd() can save a larger value in reserve and later allocate headroom using a smaller value. Moving skb->data back by reserve then places it before skb->head, and the following copy from userspace can attempt an out-of-bounds write. packet_sendmsg_spkt() has the same issue because it calculates its reservation and header offset from separate reads before dropping the RCU read lock to allocate the skb. Add LL_RESERVED_SPACE_EX() for callers that already saved a header length. Read hard_header_len once in packet_snd() and use it for allocation and construction. In packet_sendmsg_spkt(), preserve the allocation-time value through the device lookup retry. The separate SOCK_DGRAM consistency problem between hard_header_len and header_ops->create is not addressed here.
How severe is CVE-2026-74582?
Severity scoring for CVE-2026-74582 is pending analysis.
How do I fix CVE-2026-74582?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-74582?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST