Executive brief
A vulnerability in the Linux kernel's networking component could allow a local attacker to cause a system crash or potentially access restricted memory. The issue occurs when the system handles specialized memory buffers (dma-buf) that are not properly aligned to standard memory page sizes. This could impact the stability and security of systems using high-performance networking features.
Technical details
A vulnerability exists in net/core/devmem.c where net_devmem_bind_dmabuf() assumes dmabuf->size and sg_dma_len() are multiples of PAGE_SIZE. For TX operations, tx_vec is indexed based on these values; if the size is not page-aligned, net_devmem_get_niov_at() can perform an out-of-bounds read on the tx_vec array. Additionally, non-page-aligned scatter-gather lengths can desync the niov count from the gen_pool region, affecting both RX and TX paths. This is a classic bounds-checking error resulting from improper input validation of dma-buf attributes. Patches have been released for stable kernel branches including 6.18.35 and 7.0.11.
Affected products
- Linux Linux Kernel 6.16 to 6.18.35, 7.0 to 7.0.11
Timeline
- 2026-05-19: disclosed: Initial patch submission
- 2026-07-19: advisory: CVE published