Junglewise Threat Intelligence

CVE-2026-31700: Linux Kernel TOCTOU race in net/packet tpacket_snd

CVE-2026-31700 · Severity: high · CVSS 7.8 · Published 2026-05-01

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A security vulnerability exists in the Linux kernel's networking component that could allow a local attacker to bypass security checks. By exploiting a timing issue during network packet processing, an attacker could modify data after it has been validated but before it is used by the system. This could lead to unauthorized access to sensitive information or a complete system compromise.

Technical details

A TOCTOU race condition exists in tpacket_snd() within net/packet/af_packet.c when PACKET_VNET_HDR is enabled. The kernel validates the virtio_net_hdr via __packet_snd_vnet_parse() while it resides in a shared memory ring buffer (mmap'd), but subsequently re-reads the fields during virtio_net_hdr_to_skb(). A concurrent userspace thread can modify these fields between the validation and usage phases, bypassing safety checks. The fix involves copying the header to a stack-local variable before validation to ensure the data cannot be tampered with during processing. Patches have been released for various stable kernel branches including 6.6.x, 6.12.x, 6.18.x, and 7.0.x.

Affected products

  • Linux Linux Kernel 4.6 to 7.1

Timeline

  • 2026-04-18: other: Initial patch submission
  • 2026-05-01: disclosed: CVE published
  • 2026-06-19: patched: Final stable tree commits applied

References

Related threats