Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-74666

Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
22/08/2026
Última modificación:
22/08/2026

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> packet: synchronize pressure clearing with ring reconfiguration<br /> <br /> packet_set_ring() updates the RX ring state under sk_receive_queue.lock,<br /> but used to publish the tpacket receive mode through po-&gt;prot_hook.func<br /> after releasing that lock. packet_poll() and packet_recvmsg() can then<br /> run the pressure clearing path after the ring has been cleared while<br /> still seeing tpacket_rcv, causing __packet_rcv_has_room() to dereference<br /> stale or NULL ring storage.<br /> <br /> Move the existing receive hook assignment into the same<br /> sk_receive_queue.lock section as the ring state update. Keep the<br /> assignment otherwise unchanged, including on TX ring reconfiguration, to<br /> avoid adding behavior changes that are not required for the fix.<br /> <br /> Serialize packet_recvmsg() pressure clearing with the same queue lock<br /> only after PACKET_SOCK_PRESSURE has been observed. If the flag is clear<br /> and the socket has moved away from tpacket_rcv, packet_set_ring() has<br /> already detached the socket and waited for synchronize_net(), so no new<br /> packet input can set the flag again.<br /> <br /> packet_poll() already holds sk_receive_queue.lock, so it uses the new<br /> unlocked helper directly.

Impacto