Executive brief
A vulnerability exists in the Linux kernel's networking component that could allow a local attacker to crash the system or potentially execute unauthorized code. The issue occurs when the system handles a large number of virtual network interfaces (macvlans) while processing specific types of network traffic. This could lead to a service outage or compromise the integrity of the operating system in environments using advanced networking features like XDP.
Technical details
A stack-based out-of-bounds write exists in kernel/bpf/devmap.c within the get_upper_ifindexes() function. The vulnerability is caused by a lack of bounds checking when iterating over upper network devices and writing their indices into a stack-allocated array. While callers assume a maximum nesting depth (MAX_NEST_DEV), certain configurations like numerous macvlans can exceed this limit. An attacker can trigger this by creating more than 8 macvlans on a device with an XDP program using BPF_F_BROADCAST and sending a packet to trigger the redirect path. The fix introduces a maximum parameter to get_upper_ifindexes() to enforce bounds and returns -EOVERFLOW if exceeded.
Affected products
- Linux Linux Kernel Fixed in versions 5000e40, 75d4747, 88df604, 8a95fb9, b7bf516, ca83156, d2c31d8
- Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP V3.1.5, V3.1.6
- Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP V3.1.5, V3.1.6
- Siemens SIPLUS S7-1500 CPU 1518-4 PN/DP MFP V3.1.5, V3.1.6
Timeline
- 2026-02-25: disclosed: Initial patch authored
- 2026-03-25: advisory: NVD publication date
- 2026-03-25: patched: Commits merged into stable trees
References
- https://git.kernel.org/stable/c/5000e40acc8d0c36ab709662e32120986ac22e7e
- https://git.kernel.org/stable/c/75d474702b2ba8b6bcb26eb3004dbc5e95ffd5d2
- https://git.kernel.org/stable/c/88df604f0d16a692867582350ce3f2fcd22243f1
- https://git.kernel.org/stable/c/8a95fb9df1105b1618872c2846a6c01e3ba20b45
- https://git.kernel.org/stable/c/b7bf516c3ecd9a2aae2dc2635178ab87b734fef1
- https://git.kernel.org/stable/c/ca831567908fd3f73cf97d8a6c09a5054697a182
- https://git.kernel.org/stable/c/d2c31d8e03d05edc16656e5ffe187f0d1da763d7