CVE-2026-74744
Gravedad CVSS v3.1:
CRÍTICA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
26/08/2026
Última modificación:
27/08/2026
Descripción
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
ipvlan: inherit needed_headroom and needed_tailroom from phy_dev<br />
<br />
ipvlan devices inherit hard_header_len from phy_dev during ipvlan_init(),<br />
but leave needed_headroom and needed_tailroom set to 0.<br />
<br />
When the underlying phy_dev (or stacked lower device) requires extra headroom<br />
or tailroom for headers/trailers (e.g. macsec, ipsec, wireguard, tunnels, or<br />
veth with rx headroom), upper layers calculating packet headroom and tailroom<br />
fail to reserve sufficient space.<br />
<br />
This can result in reallocation overhead, skb headroom underflows, or KASAN<br />
slab-use-after-free crashes when dev_hard_header() / ipvlan_hard_header()<br />
prepends header data or when lower devices append tailroom.<br />
<br />
Fix this by:<br />
1. Inheriting needed_headroom and needed_tailroom from phy_dev in ipvlan_init().<br />
2. Propagating needed_headroom and needed_tailroom updates to attached ipvlans<br />
in ipvlan_device_event() when receiving NETDEV_FEAT_CHANGE events.
Impacto
Puntuación base 3.x
9.80
Gravedad 3.x
CRÍTICA
Referencias a soluciones, herramientas e información
- https://git.kernel.org/stable/c/5c2ca77212eb38559b0353b8363b7a84f4b019dd
- https://git.kernel.org/stable/c/5f33188457bbcc1b11ca87084037963c516ed3d9
- https://git.kernel.org/stable/c/af602c4d0ee548da18e2409b4b4da1079625a372
- https://git.kernel.org/stable/c/c0fbe31f6b20ade0465130685859faa5c86fda59
- https://git.kernel.org/stable/c/e16e960d55a40d36bd7c2494cc005e757dc9a1ef
- https://git.kernel.org/stable/c/f3c17ff65f54781cde696e16a6c577615ed735aa



