Executive brief
A vulnerability was identified in the Linux kernel's LAPB over Ethernet driver. This component is used for specific types of wide-area networking (WAN) communications. An attacker could potentially cause a system crash or denial-of-service by triggering an unexpected change in the network device type, which the driver does not currently handle correctly.
Technical details
A vulnerability exists in the Linux kernel's lapbether driver (drivers/net/wan/lapbether.c). The function lapbeth_data_transmit() assumes the underlying network device is of type ARPHRD_ETHER. However, the driver did not previously handle the NETDEV_PRE_TYPE_CHANGE event, allowing other kernel components like the bonding driver to change the device type and break this assumption. This mismatch can lead to kernel instability or a denial-of-service. The fix involves updating lapbeth_device_event() to return NOTIFY_BAD when a type change is attempted on an active lapbeth device, effectively blocking the unsupported transition. This issue was discovered via syzbot.
Affected products
- Linux Linux Kernel 2.6.24 to 6.6.136, 6.7 to 6.12.83, 6.13 to 6.18.24, 6.19 to 6.19.14, 7.0-rc1 to 7.0-rc7
Timeline
- 2026-05-06: disclosed
- 2026-05-06: advisory
- 2026-04-02: patched: Initial patch proposed by Eric Dumazet
References
- https://git.kernel.org/stable/c/328bb2cff5c2ed973f595ded769e15f4b7a117be
- https://git.kernel.org/stable/c/363a38044b8cd5b496d241651a1fb666e7c5fe3e
- https://git.kernel.org/stable/c/63851f60781aa89258c8f0952cd13940aab0888e
- https://git.kernel.org/stable/c/698642a01d53107ce9b3fc08bd801284af478a2b
- https://git.kernel.org/stable/c/a10570973619cba9dfa6d723177251b846fae587
- https://git.kernel.org/stable/c/b117056768ab7deb434e7d72065e48d2083a0c2a
- https://git.kernel.org/stable/c/b120e4432f9f56c7103133d6a11245e617695adb