Executive brief
A vulnerability exists in the Linux kernel's 'team' network driver, which is used to group multiple network interfaces into a single logical interface for redundancy or higher throughput. When using certain non-standard network configurations, the system can confuse different types of internal data structures, leading to a system crash. This could allow a local attacker to disrupt system operations or potentially gain unauthorized access to sensitive information.
Technical details
A type confusion vulnerability exists in the Linux kernel 'team' driver (drivers/net/team/team_core.c). For non-Ethernet ports, team_setup_by_port() incorrectly copies header_ops directly from the underlying port device. When the team device subsequently invokes dev_hard_header() or dev_parse_header(), the callbacks execute using the team net_device context instead of the expected lower device context. This causes netdev_priv(dev) to be misinterpreted as the wrong private data type, leading to a crash (as seen in syzbot reports involving stacked GRE, bonding, and team devices). The fix introduces header_ops wrappers that use RCU to select the correct port and ensure callbacks receive the appropriate net_device context.
Affected products
- Linux Linux 3.7 to 6.12.80, 6.18.21, 6.19.11
Timeline
- 2026-03-20: other: Initial patch authored
- 2026-04-22: advisory: CVE published
- 2026-07-24: patched: Final stable tree updates applied
References
- https://git.kernel.org/stable/c/0a7468ed49a6b65d34abcc6eb60e15f7f6d34da0
- https://git.kernel.org/stable/c/20491d384d973a63fbdaf7a71e38d69b0659ea55
- https://git.kernel.org/stable/c/420e5aad7ba89e8f79e2dc8327b0c0c24c1c1d53
- https://git.kernel.org/stable/c/425000dbf17373a4ab8be9428f5dc055ef870a56
- https://git.kernel.org/stable/c/6d3161fa3eee64d46b766fb0db33ec7f300ef52d