Executive brief
A race condition in the Linux kernel's packet socket implementation allows concurrent modification of device header length during packet transmission, leading to memory corruption. An attacker with local network access could trigger out-of-bounds writes during packet construction, potentially achieving denial of service or privilege escalation.
Technical details
The vulnerability exists in packet_snd() and packet_sendmsg_spkt() functions in the AF_PACKET socket implementation. These functions read dev->hard_header_len multiple times during socket buffer (skb) allocation and construction without holding a consistent value. Device reconfiguration (such as bonding type changes) can modify this value concurrently between the reads. For SOCK_RAW sockets, a larger header length can be saved for memory reservation, but a smaller value used for actual allocation, causing skb->data to be positioned before skb->head. Subsequent userspace copy operations then perform out-of-bounds writes. The fix introduces LL_RESERVED_SPACE_EX() macro and ensures hard_header_len is read once and reused throughout both packet_snd() and packet_sendmsg_spkt() functions. Patches have been committed to the Linux kernel mainline and stable branches.
Affected products
- Linux Linux Kernel All versions prior to fix (patched in mainline and stable branches as of 2026-08-06)
Timeline
- 2026-08-21: disclosed
- 2026-08-06: patched: Patch committed to mainline by Jakub Kicinski