CVE-2026-74743

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
26/08/2026
Last modified:
27/08/2026

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> macvlan: inherit needed_headroom and needed_tailroom from lowerdev<br /> <br /> macvlan devices inherit hard_header_len from lowerdev during macvlan_init(),<br /> but leave needed_headroom and needed_tailroom set to 0.<br /> <br /> When the underlying lowerdev requires extra headroom or tailroom for<br /> headers/trailers (e.g. macsec, ipsec, wireguard, tunnels, or veth with rx<br /> headroom), upper layers calculating packet headroom and tailroom fail to<br /> reserve sufficient space.<br /> <br /> This can result in reallocation overhead, skb headroom underflows, or KASAN<br /> slab-use-after-free crashes when dev_hard_header() / macvlan_hard_header()<br /> prepends header data or when lower devices append tailroom.<br /> <br /> Fix this by:<br /> 1. Inheriting needed_headroom and needed_tailroom from lowerdev in macvlan_init().<br /> 2. Propagating needed_headroom and needed_tailroom updates to attached macvlans<br /> in macvlan_device_event() when receiving NETDEV_FEAT_CHANGE events.