Executive brief
The Linux kernel's traffic control flow classifier component used weak pointer hashing that allowed unprivileged users in isolated namespaces to recover kernel memory addresses. By manipulating classifier parameters and observing statistics, an attacker could leak sensitive pointer values (socket, routing, and netfilter connection tracking pointers), potentially aiding privilege escalation or other kernel exploits. The fix replaces the weak XOR folding with cryptographically secure hashing.
Technical details
The vulnerability exists in the net/sched/cls_flow.c traffic control classifier, which uses a fallback addr_fold() function to hash kernel pointers (skb->sk, skb_dst(), skb_nfct()) for fields missing from packet headers. The original implementation employed simple XOR folding: masking the lower 32 bits and XORing with the upper 32 bits if on a 64-bit system. In map mode, unprivileged userspace can control mask, xor, rshift, addend, and divisor parameters, and observe the resulting classid via class statistics, allowing recovery of the 32-bit folded pointer value. The fix replaces addr_fold() with keyed siphash (a cryptographically secure hash function initialized with a random secret), preventing pointer leak recovery. The patch has been applied across stable kernel branches.
Affected products
- Linux Linux kernel Multiple versions (2.6.11 through 6.x and 7.x)
Timeline
- 2026-08-15: disclosed
- 2026-07-24: patched