CVE-2026-74744

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
26/08/2026
Last modified:
27/08/2026

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> ipvlan: inherit needed_headroom and needed_tailroom from phy_dev<br /> <br /> ipvlan devices inherit hard_header_len from phy_dev during ipvlan_init(),<br /> but leave needed_headroom and needed_tailroom set to 0.<br /> <br /> When the underlying phy_dev (or stacked lower device) requires extra headroom<br /> or tailroom for headers/trailers (e.g. macsec, ipsec, wireguard, tunnels, or<br /> veth with rx headroom), upper layers calculating packet headroom and tailroom<br /> fail to reserve sufficient space.<br /> <br /> This can result in reallocation overhead, skb headroom underflows, or KASAN<br /> slab-use-after-free crashes when dev_hard_header() / ipvlan_hard_header()<br /> prepends header data or when lower devices append tailroom.<br /> <br /> Fix this by:<br /> 1. Inheriting needed_headroom and needed_tailroom from phy_dev in ipvlan_init().<br /> 2. Propagating needed_headroom and needed_tailroom updates to attached ipvlans<br /> in ipvlan_device_event() when receiving NETDEV_FEAT_CHANGE events.