Executive brief
A vulnerability in the Linux kernel's networking component could allow an attacker to cause a system crash. The issue occurs when processing specific types of UDP network traffic using BPF programs, leading to a kernel panic. This primarily impacts the availability of the affected server or device.
Technical details
A general protection fault occurs in the Linux kernel's UDP receive path due to a memory aliasing issue in the sk_buff structure. In the UDP path, skb->dev is repurposed as dev_scratch via a union. When a UDP socket is in a sockmap and an attached BPF SK_SKB verdict program calls socket-lookup helpers (like bpf_sk_lookup_tcp), the kernel attempts to dereference skb->dev as a pointer. Because it still contains the dev_scratch integer value rather than a valid memory address, the kernel triggers a general protection fault in softirq context. The fix involves explicitly clearing skb->dev before running the sockmap verdict to ensure the lookup helper falls back to using the socket's network namespace.
Affected products
- Linux Linux Kernel 7.1.0-rc6
Timeline
- 2026-06-03: disclosed: Patch submitted by Sechang Lim
- 2026-06-19: patched: Committed to stable tree by Greg Kroah-Hartman
- 2026-06-25: advisory
References
- https://git.kernel.org/stable/c/1b585673a2249f13678e7ac443ac683ba767e0b6
- https://git.kernel.org/stable/c/263779a6beff03b8b06f6d25566cb0f45af361f2
- https://git.kernel.org/stable/c/3c94f241f776562c489876ff506f366224565c21
- https://git.kernel.org/stable/c/6822eed69572000a181fa4e31fceacc60918c471
- https://git.kernel.org/stable/c/7d6d92d000ebe3a845a17c165c1d3a70c5d84fe1
- https://git.kernel.org/stable/c/90d35188aaa92b8f8b23f66335e0e91bf60103a3