From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 87A924CCDC8 for ; Thu, 3 Sep 2026 08:27:17 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788424038; cv=none; b=ZWBj13Pu8llSIwsX7NjeH+NTPGZvlJg+7GiwXMqlmXxs0hBOAxYxsRqPEw3WbbjGanC7MlVi3JM8gbCRs2Q0PQBm4Varq9ZUxARGJKH1dsUYUqC/YeDVwH04BxlcagZe/nfSjVIWzkzBIBl0/f6cqcd5tp8qxwRPU0mxH11uv9Y= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788424038; c=relaxed/simple; bh=gKxK1+GcCaM8ZtUvHz7Rp4crB40OTBiSUMI4ewdS4bM=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=cihXBcSPiMjbjYSuhUqhFapwlCs6IIjxPb8vGAdd99pGtVyJbErZ9/TCJWEF1Ybk2yOtZ9eVry0YC8BkeAW7jFKBKM2sZA95C32koM9Nh/SeNptVNCOZ+RVF/eeGnAJm9PPETOO0I0+OCFOI2SXOrSprxL+9hIulBJmSWlD6d18= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=1jJfmXEP; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="1jJfmXEP" Received: by smtp.kernel.org (Postfix) with ESMTPSA id CDE641F000E9; Thu, 3 Sep 2026 08:27:16 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1788424037; bh=MdgWR73PQXp5CUNhnQvhKWj8Epd9Dh4OZCsNnAGDXLI=; h=From:To:Cc:Subject:Date:Reply-To; b=1jJfmXEPy5gcxuUXCzKzPwzRFFyrvsqfAVNhEVsb37M4YgrfrJcIWosy165fg57Ad LrAGuMtTbhE7xUWJ2PLndFVW4z4d5lzS+palgnnmp63fe3Eko4gKzLVOxy2aU0qJAy n5VQZuIuQQmsjR+Kx975lSaq62316nkDK/YsjiXA= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-80742: af_packet: Don't send zero-byte data in tpacket_snd(). Date: Thu, 3 Sep 2026 10:26:39 +0200 Message-ID: <2026090337-CVE-2026-80742-b1e2@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=4280; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=VGi5+iwKydDgRiU2aythaFC2mB8WeytFaQnaq5xjeiw=; b=owGbwMvMwCRo6H6F97bub03G02pJDFkz9W3P5DpWRHt0bJ2/e7nz3vJy4bj1Ie/XhwokzXn+s aLvZcyJjlgWBkEmBlkxRZYv23iO7q84pOhlaHsaZg4rE8gQBi5OAZhIvwvDgsuCbtlv3zS+YLRk mMvs+eJj0B2D1QwLdmy7oeT8fNoCg+NvolYGV/O1etX3AgA= X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: af_packet: Don't send zero-byte data in tpacket_snd(). syzbot reported a WARNING in __dev_queue_xmit() triggered via tpacket_snd(): skb_assert_len WARNING: at include/linux/skbuff.h:2753 skb_assert_len WARNING: at __dev_queue_xmit+0x21bc/0x4970 net/core/dev.c:4781 Call Trace: dev_queue_xmit include/linux/netdevice.h:3448 [inline] packet_xmit+0x243/0x310 net/packet/af_packet.c:276 tpacket_snd net/packet/af_packet.c:2907 [inline] packet_sendmsg+0x28d6/0x4eb0 net/packet/af_packet.c:3134 When sending 0-byte packets via TPACKET ring buffer on devices with no hard header (e.g. dev->hard_header_len == 0), tpacket_fill_skb() populates an skb with skb->len == 0 and returns 0. tpacket_snd() then forwards this empty skb to packet_xmit(), causing __dev_queue_xmit() to hit skb_assert_len(skb). Similar checks exist in packet_snd() via commit dc633700f00f ("net/af_packet: check len when min_header_len equals to 0") and in packet_sendmsg_spkt() via commit 6a341729fb31 ("af_packet: Don't send zero-byte data in packet_sendmsg_spkt()."). Return -EINVAL in tpacket_fill_skb() when skb->len is zero to reject zero-length packets in tpacket_snd(). The Linux kernel CVE team has assigned CVE-2026-80742 to this issue. Affected and fixed versions =========================== Issue introduced in 2.6.12 with commit 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and fixed in 5.10.266 with commit dde212f8622f5cb36223fff1ebd6e6f2a3dc61fe Issue introduced in 2.6.12 with commit 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and fixed in 5.15.217 with commit 80a702964467b998d254f16cc61c2c9a20540c9d Issue introduced in 2.6.12 with commit 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and fixed in 6.1.184 with commit 7521e691c7c4f2231634c95053281ac888d1f452 Issue introduced in 2.6.12 with commit 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and fixed in 6.6.153 with commit 1fc70b3d513bafb16b17540178870ef46e81c0bb Issue introduced in 2.6.12 with commit 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and fixed in 6.12.105 with commit 3fa110f9e2ea96f567f2194c673c4bc327640111 Issue introduced in 2.6.12 with commit 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and fixed in 6.18.46 with commit 98c5914d6b7bd4b4675535908e57dea31f1efd6a Issue introduced in 2.6.12 with commit 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and fixed in 7.1.10 with commit f09ac5682f1bb67981fcb6ead4d3cfe439225876 Issue introduced in 2.6.12 with commit 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and fixed in 7.2 with commit 6bcd76c134c55c697148acb5c0194e9666abdf84 Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-80742 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: net/packet/af_packet.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/dde212f8622f5cb36223fff1ebd6e6f2a3dc61fe https://git.kernel.org/stable/c/80a702964467b998d254f16cc61c2c9a20540c9d https://git.kernel.org/stable/c/7521e691c7c4f2231634c95053281ac888d1f452 https://git.kernel.org/stable/c/1fc70b3d513bafb16b17540178870ef46e81c0bb https://git.kernel.org/stable/c/3fa110f9e2ea96f567f2194c673c4bc327640111 https://git.kernel.org/stable/c/98c5914d6b7bd4b4675535908e57dea31f1efd6a https://git.kernel.org/stable/c/f09ac5682f1bb67981fcb6ead4d3cfe439225876 https://git.kernel.org/stable/c/6bcd76c134c55c697148acb5c0194e9666abdf84