Executive brief
The Linux kernel's flow dissector module unconditionally reads Ethernet header data from network packets without verifying the packet actually has an Ethernet header. This can be exploited on certain virtual network devices (like TUN in L3 mode) to read uninitialized kernel memory and cause system instability or information disclosure. An attacker with the ability to send crafted packets through affected virtual network devices could trigger kernel crashes or expose sensitive data.
Technical details
The vulnerability is a buffer over-read in the __skb_flow_dissect() function in the Linux kernel's flow_dissector subsystem. When the FLOW_DISSECTOR_KEY_ETH_ADDRS flow key is requested, the code unconditionally memcpys 12 bytes from the Ethernet header without first verifying that the packet has a valid Ethernet header. On layer-3 virtual devices (TUN in L3 mode) with hard_header_len=0, the mac_header points into the L3 data area, causing the function to read uninitialized skb memory. The uninitialized data propagates through fl_set_masked_key() and is used as a rhashtable lookup key in __fl_lookup(), potentially causing information disclosure detected by KMSAN. The fix gateways the memcpy operation on dev->type == ARPHRD_ETHER and checks skb_mac_header_was_set() to prevent wild pointer dereference. Attack preconditions include creating a TUN device in L3 mode, attaching a multiq qdisc with a flower filter matching on eth_src, and sending packets via AF_PACKET.
Affected products
- Linux Linux kernel multiple versions prior to fix
Timeline
- 2026-08-15: disclosed: CVE-2026-72444 published
- 2026-08-15: patched: Fix committed to resolve flow_dissector device type check