Description
In the Linux kernel, the following vulnerability has been resolved:

packet: use consistent hard_header_len in non-ring send paths

packet_snd() reads dev->hard_header_len multiple times while allocating
and constructing an skb. Device reconfiguration can change this value
concurrently, for example through bonding device type changes.

For SOCK_RAW, packet_snd() can save a larger value in reserve and later
allocate headroom using a smaller value. Moving skb->data back by reserve
then places it before skb->head, and the following copy from userspace can
attempt an out-of-bounds write.

packet_sendmsg_spkt() has the same issue because it calculates its
reservation and header offset from separate reads before dropping the RCU
read lock to allocate the skb.

Add LL_RESERVED_SPACE_EX() for callers that already saved a header length.
Read hard_header_len once in packet_snd() and use it for allocation and
construction. In packet_sendmsg_spkt(), preserve the allocation-time value
through the device lookup retry.

The separate SOCK_DGRAM consistency problem between hard_header_len and
header_ops->create is not addressed here.
Published: 2026-08-21
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Local Privilege Escalation
Action: Patch Immediately
AI Analysis

Impact

The vulnerability arises in the Linux kernel’s packet socket implementation, where the device’s hard_header_len value is read multiple times during socket buffer allocation and construction. If a network device is reconfigured concurrently—for example, during bonding mode changes—the value may change between reads. In raw sockets, a larger reserve can be stored while a smaller headroom value is used later. This can shift the buffer data before the allocated head, and a subsequent copy from user space may perform an out‑of‑bounds write, corrupting kernel memory. A similar race exists in packet_sendmsg_spkt, where the reservation and header offset are calculated from separate reads before the RCU read lock is released.

Affected Systems

All Linux kernel releases that have not incorporated the advisory’s commit series are potentially vulnerable, including any vendor distribution that includes the unpatched packet socket implementation. Specific kernel versions are not enumerated in the advisory, so any kernel version lacking the fixes should be considered at risk.

Risk and Exploitability

The CVSS score of 7.8 reflects a high severity, while the EPSS score is reported at < 1% (approximately 0.00156), indicating a very low probability of exploitation currently; the vulnerability is not listed in the CISA KEV catalog. The flaw requires an attacker to send crafted packets or bind raw packet sockets, which typically demands local system access or network privileges. The race condition can lead to kernel memory corruption, enabling an attacker to elevate privileges to root if the out‑of‑bounds write targets critical structures. Because the exploit is local and relies on concurrent device reconfiguration, the threat is moderate to high for environments that use raw or packet sockets.

Generated by OpenCVE AI on August 25, 2026 at 06:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply a kernel update that incorporates the commit series referenced in the advisory
  • Restrict the use of packet and raw sockets for untrusted processes by disabling CAP_NET_RAW and related capabilities
  • Avoid dynamic network device reconfiguration during critical socket operations; consider disabling bonding reassignment or locking the device configuration when packet sockets are active

Generated by OpenCVE AI on August 25, 2026 at 06:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4777-1 linux security update
Debian DSA Debian DSA DSA-6466-1 linux security update
History

Thu, 27 Aug 2026 13:00:00 +0000


Tue, 25 Aug 2026 05:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.0, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Sat, 22 Aug 2026 02:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-122
CWE-680

Sat, 22 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.0, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}

threat_severity

Important


Fri, 21 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-122
CWE-680

Fri, 21 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: packet: use consistent hard_header_len in non-ring send paths packet_snd() reads dev->hard_header_len multiple times while allocating and constructing an skb. Device reconfiguration can change this value concurrently, for example through bonding device type changes. For SOCK_RAW, packet_snd() can save a larger value in reserve and later allocate headroom using a smaller value. Moving skb->data back by reserve then places it before skb->head, and the following copy from userspace can attempt an out-of-bounds write. packet_sendmsg_spkt() has the same issue because it calculates its reservation and header offset from separate reads before dropping the RCU read lock to allocate the skb. Add LL_RESERVED_SPACE_EX() for callers that already saved a header length. Read hard_header_len once in packet_snd() and use it for allocation and construction. In packet_sendmsg_spkt(), preserve the allocation-time value through the device lookup retry. The separate SOCK_DGRAM consistency problem between hard_header_len and header_ops->create is not addressed here.
Title packet: use consistent hard_header_len in non-ring send paths
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-27T12:39:47.499Z

Reserved: 2026-08-15T05:44:03.918Z

Link: CVE-2026-74582

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-21T17:16:44.507

Modified: 2026-08-27T13:18:34.533

Link: CVE-2026-74582

cve-icon Redhat

Severity : Important

Publid Date: 2026-08-21T00:00:00Z

Links: CVE-2026-74582 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T07:00:08Z

Weaknesses