Executive brief
The Linux kernel's AF_XDP (XDP socket) subsystem used for high-performance packet processing contained a flaw in metadata validation for zero-copy transmit operations. An attacker with access to AF_XDP sockets could manipulate TX metadata after initial validation to bypass security checks, potentially allowing unauthorized packet transmission or triggering undefined kernel behavior that could lead to denial of service or privilege escalation.
Technical details
A time-of-check-time-of-use (TOCTOU) vulnerability exists in the XDP socket zero-copy TX path. The kernel validates TX metadata once when obtaining the descriptor context, but user-space applications can modify the metadata before it is read again during hardware request preparation, allowing the modified values to bypass the original validation checks. The fix moves metadata validation into xsk_tx_metadata_request() and creates a snapshot of validation flags used consistently across all feature checks, ensuring only values observed after validation are processed by zero-copy drivers (Intel IGC, Mellanox MLX5, STMicro STMMac). The vulnerability requires local access and ability to use AF_XDP sockets but no special privileges.
Affected products
- Linux Linux kernel versions containing XDP socket metadata support (introduced in kernel 6.4 era, affecting 5.15+ with backports)
Timeline
- 2026-08-22: disclosed
- 2026-07-27: patched: Upstream fix committed
- 2026-08-22: advisory: CVE-2026-74707 published