Executive brief
The Linux kernel's XDP (eXpress Data Path) networking component contains a memory safety vulnerability in how it clones network frames for broadcast operations. A maliciously crafted or edge-case network packet could cause the kernel to corrupt memory used for packet metadata, potentially leading to system crashes or unauthorized access to kernel memory. This affects systems using kernel-based networking acceleration features.
Technical details
The vulnerability exists in the xdpf_clone() function in net/core/xdp.c, which clones XDP frames into a single page allocation. The original validation only checked if the frame's header, headroom, and payload fit within PAGE_SIZE, but did not account for the skb_shared_info structure that must reside at the end of the buffer. An attacker can craft a source frame backed by a larger allocation that passes the incomplete check but extends into the reserved skb_shared_info tailroom area. When __xdp_build_skb_from_frame() later converts the clone back to a socket buffer, build_skb_around() places skb_shared_info over live packet data, causing subsequent writes to corrupt kernel memory. The fix tightens the validation to reject clones whose linear area does not fit within SKB_WITH_OVERHEAD(PAGE_SIZE), ensuring proper tailroom reservation. This is a network-adjacent vulnerability requiring control over packet content.
Affected products
- Linux Linux kernel 3.2.y through 7.2.y (XDP broadcast support introduced in e624d4ed4aa8)
Timeline
- 2026-08-22: disclosed
- 2026-08-19: patched: Fix commit 58408982fa39f9758124cec169f42854d6f98f35 merged by Greg Kroah-Hartman