Executive brief
A vulnerability in the Linux kernel's networking subsystem could allow a local user to crash the system. The issue occurs when specific network traffic redirection rules (mirred blockcast) are configured in a way that creates an infinite loop, exhausting the system's memory stack. This results in a kernel panic, leading to a complete system outage or denial of service.
Technical details
A stack overflow vulnerability exists in net/sched/act_mirred.c due to a logic error in recursion limiting. The function tcf_mirred_act() implements a nesting limit (MIRRED_NEST_LIMIT) to prevent infinite loops; however, when the 'blockcast' action is used, the function returns before the recursion counter is incremented. An attacker with CAP_NET_ADMIN privileges (which can be obtained by unprivileged users via user and network namespaces) can configure shared TC egress blocks to trigger an infinite loop between devices. This results in a kernel panic when the task stack guard page is hit. The fix involves moving the counter increment before the blockcast call.
Affected products
- Linux Linux Kernel 906736728cea480a85803c67fafb1b0e78491922 to 25fc9352590f5ef21ebf290432bd768b336693bc, fe946a751d9b52b7c45ca34899723b314b79b249 to 34457de389fb64a01fdcc71177dfebe65fd2d362, fe946a751d9b52b7c45ca34899723b314b79b249 to a005fa5d7502eefec7ee6e1c01adadc06de2f9ad
Timeline
- 2026-05-25: other: Patch authored
- 2026-07-19: disclosed: CVE published