CVE-2026-74743
Gravedad CVSS v3.1:
CRÍTICA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
26/08/2026
Última modificación:
27/08/2026
Descripción
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
macvlan: inherit needed_headroom and needed_tailroom from lowerdev<br />
<br />
macvlan devices inherit hard_header_len from lowerdev during macvlan_init(),<br />
but leave needed_headroom and needed_tailroom set to 0.<br />
<br />
When the underlying lowerdev requires extra headroom or tailroom for<br />
headers/trailers (e.g. macsec, ipsec, wireguard, tunnels, or veth with rx<br />
headroom), upper layers calculating packet headroom and tailroom fail to<br />
reserve sufficient space.<br />
<br />
This can result in reallocation overhead, skb headroom underflows, or KASAN<br />
slab-use-after-free crashes when dev_hard_header() / macvlan_hard_header()<br />
prepends header data or when lower devices append tailroom.<br />
<br />
Fix this by:<br />
1. Inheriting needed_headroom and needed_tailroom from lowerdev in macvlan_init().<br />
2. Propagating needed_headroom and needed_tailroom updates to attached macvlans<br />
in macvlan_device_event() when receiving NETDEV_FEAT_CHANGE events.
Impacto
Puntuación base 3.x
9.80
Gravedad 3.x
CRÍTICA
Referencias a soluciones, herramientas e información
- https://git.kernel.org/stable/c/28afc87bd8da0b3348bbbd834c8a89e83712cf5e
- https://git.kernel.org/stable/c/8cd90e850e434577bf6774778657d26d6995e53f
- https://git.kernel.org/stable/c/8f6a05dbac05725e0786701eb04778c5bdbe4eaa
- https://git.kernel.org/stable/c/96fa90b74385b7f2b0d97251dd43d5ee6ca44668
- https://git.kernel.org/stable/c/bc9a00fb78e32bccc39d763bfd13a450705bac5d
- https://git.kernel.org/stable/c/cef51860becd9700217c81732ca1eb1ea6ed6fe1



