CVE-2026-74668
Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
22/08/2026
Última modificación:
22/08/2026
Descripción
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
packet: use consistent hard_header_len in TX_RING send path<br />
<br />
tpacket_snd() reads dev->hard_header_len independently for skb<br />
allocation and header construction in tpacket_fill_skb(). Concurrent<br />
netdevice reconfiguration can therefore make the reserved headroom<br />
smaller than the amount later pushed, or make copylen - hard_header_len<br />
negative.<br />
<br />
Snapshot hard_header_len once before processing ring frames and use it<br />
for the frame limit, headroom allocation, copy length, and skb<br />
construction. Pass the snapshot to tpacket_fill_skb().<br />
<br />
The separate SOCK_DGRAM consistency problem between hard_header_len and<br />
header_ops->create is not addressed here.
Impacto
Referencias a soluciones, herramientas e información
- https://git.kernel.org/stable/c/016763e829cac37b3234eace86fd0a4c560de4a7
- https://git.kernel.org/stable/c/21b5953e7494c16a42e6cd8cf110e18d13ae4a6b
- https://git.kernel.org/stable/c/27e068d1b35dbec10a3cf268887c94407be4badc
- https://git.kernel.org/stable/c/d48ea5c9c4c34dc0df621f0e39ed3a16b644621a
- https://git.kernel.org/stable/c/d85d2fd54e901637c81d847811e03c662aee13cd


