Executive brief
A vulnerability exists in the Linux kernel's network bonding driver, which is used to combine multiple network interfaces into a single logical link for redundancy or increased throughput. A flaw in how the system handles broadcast traffic can lead to a system crash or potential unauthorized access to memory. This could allow a local attacker to disrupt network operations or compromise the stability of the server.
Technical details
A use-after-free (UAF) vulnerability exists in bond_xmit_broadcast() within the Linux kernel's bonding driver (drivers/net/bonding/bond_main.c). The function reuses the original socket buffer (skb) for the 'last' slave interface while cloning it for others. However, the bond_is_last_slave() check is racy; if the slave list is mutated (via enslave or release operations) during RCU-protected iteration, the 'last' determination can change mid-loop. This results in the original skb being consumed multiple times, leading to a double-free or UAF. The fix replaces the racy check with a stable index comparison against a pre-loop snapshot of the slave count. An attacker with local access could trigger this race condition to cause a kernel panic (KASAN: slab-use-after-free) or potentially achieve privilege escalation.
Affected products
- Linux Linux kernel 5.10.94 to 5.11; 5.15.17 to 5.16; 5.16.3 to 5.17; 5.17 to 6.12.86; 6.13 to 6.18.22; 6.19 to 6.19.12; 7.0-rc1 to 7.0-rc6
Timeline
- 2026-03-26: other: Patch submitted by developer
- 2026-04-13: advisory: CVE published by kernel.org
- 2026-05-07: patched: Patch merged into stable branches