Junglewise Threat Intelligence

CVE-2026-31502: Linux Kernel team driver type confusion in non-Ethernet ports

CVE-2026-31502 · Severity: high · CVSS 7.8 · Published 2026-04-22

Technologies: Linux. Vendors: Linux.

Executive brief

A vulnerability exists in the Linux kernel's 'team' network driver, which is used to group multiple network interfaces into a single logical interface for redundancy or higher throughput. When using certain non-standard network configurations, the system can confuse different types of internal data structures, leading to a system crash. This could allow a local attacker to disrupt system operations or potentially gain unauthorized access to sensitive information.

Technical details

A type confusion vulnerability exists in the Linux kernel 'team' driver (drivers/net/team/team_core.c). For non-Ethernet ports, team_setup_by_port() incorrectly copies header_ops directly from the underlying port device. When the team device subsequently invokes dev_hard_header() or dev_parse_header(), the callbacks execute using the team net_device context instead of the expected lower device context. This causes netdev_priv(dev) to be misinterpreted as the wrong private data type, leading to a crash (as seen in syzbot reports involving stacked GRE, bonding, and team devices). The fix introduces header_ops wrappers that use RCU to select the correct port and ensure callbacks receive the appropriate net_device context.

Affected products

  • Linux Linux 3.7 to 6.12.80, 6.18.21, 6.19.11

Timeline

  • 2026-03-20: other: Initial patch authored
  • 2026-04-22: advisory: CVE published
  • 2026-07-24: patched: Final stable tree updates applied

References