Executive brief
A vulnerability in the Linux kernel's networking component could allow a local user to crash the system. By sending specially crafted network packets that contain invalid header information, an attacker can trigger a kernel panic, leading to a complete denial of service. This issue affects systems where users have permissions to create raw network sockets, which is common in certain containerized or administrative environments.
Technical details
A vulnerability exists in the raw_send_hdrinc() function in net/ipv4/raw.c where the kernel fails to reject IPv4 packets with an Internet Header Length (IHL) less than 5. When a malformed packet with ihl < 5 is processed, downstream consumers like ah_output() in net/ipv4/ah4.c perform calculations that result in a negative signed integer. When this value is cast to a size_t for a memcpy() operation, it results in an extremely large out-of-bounds access, causing a host kernel panic. The attack requires CAP_NET_RAW, which can be obtained by unprivileged processes in environments with user and network namespaces enabled (CONFIG_USER_NS=y). The issue has been resolved by adding a check to reject packets where iphlen is less than the size of the IPv4 header.
Affected products
- Linux Linux Kernel Introduced in 2.6.12-rc2; fixed in various stable branches including 6.x, 5.x, 4.x
Timeline
- 2026-05-12: disclosed: Initial patch submission by Michael Bommarito
- 2026-06-01: patched: Patch committed to stable branches by Greg Kroah-Hartman
- 2026-07-19: advisory: CVE-2026-64114 published
References
- https://git.kernel.org/stable/c/1065b9efa4126df559b03a849c139ecfae92cd25
- https://git.kernel.org/stable/c/145e9afa5b905229b4788bb72c3255f5a5f77508
- https://git.kernel.org/stable/c/3c5411fa4944ed99af3d9d1de750ea8169b6dac9
- https://git.kernel.org/stable/c/5a564f737ec54d63e8ee221d3ff396d07586d464
- https://git.kernel.org/stable/c/7725cd3b471740fd23d25ed1da722c671fb2a5d3
- https://git.kernel.org/stable/c/915fab69823a14c170dbaa3b41978768e0fe62fc
- https://git.kernel.org/stable/c/bbe0be67de296176e7243c76e3d9f02f6ae9ff0b