Executive brief
A vulnerability exists in the Linux kernel's high-performance networking component (AF_XDP). A local attacker could manipulate shared memory to bypass security checks, potentially causing the system to crash or access restricted memory during network data processing. This could impact the stability and reliability of servers using specialized high-speed networking.
Technical details
A TOCTOU vulnerability exists in net/xdp/xsk.c within the xsk_skb_metadata() function. The TX metadata area resides in a UMEM buffer that is memory-mapped and concurrently writable by userspace. The kernel reads 'csum_start' and 'csum_offset' twice: once for bounds validation and again for skb assignment. A malicious userspace application can race to overwrite these values between the two reads, bypassing the validation and causing out-of-bounds memory access during checksum computation in the transmit path. The fix introduces local caching of these values using READ_ONCE() to ensure the validated value is the same one used for assignment.
Affected products
- Linux Linux Kernel 6.8 to 6.18.35, 7.0 to 7.0.12
Timeline
- 2026-06-25: disclosed
- 2026-06-25: advisory