Junglewise Threat Intelligence

CVE-2026-74709: Linux kernel XSK metadata timestamp race condition

CVE-2026-74709 · Severity: info · Published 2026-08-22

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's XDP Socket (XSK) subsystem used for high-performance packet processing had a logic flaw where timestamps could be written to packet metadata even when not explicitly requested. A user-space application could change metadata flags after initial request processing, causing the kernel to incorrectly record a timestamp on packet completion. This could lead to incorrect timestamp data being exposed to applications relying on XDP offload features.

Technical details

The vulnerability is a time-of-check-time-of-use (TOCTOU) race condition in the XSK TX metadata handling code. The kernel checks the XDP_TXMD_FLAGS_TIMESTAMP flag during request processing but re-reads it during completion, allowing user space to change the flag between these two points. This causes the kernel to write a timestamp to the metadata completion structure even when the original request did not include the timestamp flag. The fix clears the metadata pointer during request processing if timestamp completion is not requested, ensuring completion handling uses the cleared pointer instead of re-reading potentially changed flags. The vulnerability affects XSK transmit path metadata handling, particularly in the mlx5 multi-packet WQE path.

Affected products

  • Linux Linux kernel Multiple versions with XSK/XDP support (fixed in upstream and stable branches)

Timeline

  • 2026-08-22: disclosed
  • 2026-08-03: patched: Upstream fix commit 9f60a67df8d3c862503bee62bada8e7089cba438
  • 2026-08-19: other: Stable release with backported fix

References

Related threats