All of lore.kernel.org
 help / color / mirror / Atom feed
* CVE-2026-80731: net: remove CAP_SYS_RAWIO zero-padding in dev_validate_header
@ 2026-09-03  8:22 Greg Kroah-Hartman
  0 siblings, 0 replies; only message in thread
From: Greg Kroah-Hartman @ 2026-09-03  8:22 UTC (permalink / raw)
  To: linux-cve-announce; +Cc: Greg Kroah-Hartman

From: Greg Kroah-Hartman <gregkh@kernel.org>

Description
===========

In the Linux kernel, the following vulnerability has been resolved:

net: remove CAP_SYS_RAWIO zero-padding in dev_validate_header

dev_validate_header() reads dev->hard_header_len directly when
zero-padding short link layer headers for CAP_SYS_RAWIO holders:

    if (capable(CAP_SYS_RAWIO)) {
        memset(ll_header + len, 0, dev->hard_header_len - len);
        return true;
    }

Packet send paths call dev_validate_header() on skbs whose headroom was
allocated from an earlier hard_header_len read. If the device is
reconfigured so that dev->hard_header_len increases before validation,
the memset writes past the reserved buffer, an out-of-bounds write.

This out-of-bounds write is masked in some SOCK_RAW paths today because
the same concurrent increase can first make skb_push() exceed the
reserved headroom and trigger skb_under_panic(). Remove the zero-padding
branch before making those hard_header_len reads consistent, so the
snapshot fixes do not turn a loud panic into a silent overwrite.

This path is only reached for variable length L2 protocols, where
len < hard_header_len but len >= min_header_len. No remaining in-tree
variable length L2 protocol implements header_ops->validate, and the
CAP_SYS_RAWIO bypass that zero-pads and accepts short headers has no
real value beyond allowing testing of intentionally malformed input.

Drop the CAP_SYS_RAWIO branch. The remaining reads of
dev->hard_header_len in dev_validate_header() are comparisons only and
have no memory safety impact.

The Linux kernel CVE team has assigned CVE-2026-80731 to this issue.


Affected and fixed versions
===========================

	Issue introduced in 3.2.80 with commit b5518429e70cd783b8ca52335456172c1a0589f6 and fixed in 3.2.81 with commit 53fd7f912c0877647d6a1e1877f5ea8535ee0b4a
	Issue introduced in 4.6 with commit 2793a23aacbd754dbbb5cb75093deb7e4103bace and fixed in 5.10.265 with commit fa6d98dd925e72fc028b26a0cbbff9d2f0601ff6
	Issue introduced in 4.6 with commit 2793a23aacbd754dbbb5cb75093deb7e4103bace and fixed in 5.15.216 with commit 8fc9816404166a90ed8d544dc52482fafffb6d9f
	Issue introduced in 4.6 with commit 2793a23aacbd754dbbb5cb75093deb7e4103bace and fixed in 6.1.183 with commit b0f92a5731dc82556a9ae005cc35f71ab136307b
	Issue introduced in 4.6 with commit 2793a23aacbd754dbbb5cb75093deb7e4103bace and fixed in 6.6.152 with commit 99df6b7a713f96eda206680d100b76e15f9d9b69
	Issue introduced in 4.6 with commit 2793a23aacbd754dbbb5cb75093deb7e4103bace and fixed in 6.12.104 with commit 74e035f07f53feca09e2352e77fccb09cad5e208
	Issue introduced in 4.6 with commit 2793a23aacbd754dbbb5cb75093deb7e4103bace and fixed in 6.18.45 with commit dbb30dc943a93e083f1e531bfdc6779e57de40d0
	Issue introduced in 4.6 with commit 2793a23aacbd754dbbb5cb75093deb7e4103bace and fixed in 7.1.9 with commit fc902f52a02298c7432b2334c0c82a2885a1a8b6
	Issue introduced in 4.6 with commit 2793a23aacbd754dbbb5cb75093deb7e4103bace and fixed in 7.2 with commit 3b9a324e646d3657a8d9806dfbfe4f3e4066e882
	Issue introduced in 3.16.36 with commit f58a6c08ebdfa978178bbca78c2ba744a2665912
	Issue introduced in 4.1.28 with commit 1df16498dfd0d5a129bdf2982d9a08df73e8923d
	Issue introduced in 4.4.8 with commit 8b8d278aa4de9335682bbd4a3bb619af015c859e
	Issue introduced in 4.5.2 with commit 6804052fa9d86e9a512c88b24a5debbfc1a490fc

Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.

Unaffected versions might change over time as fixes are backported to
older supported kernel versions.  The official CVE entry at
	https://cve.org/CVERecord/?id=CVE-2026-80731
will be updated if fixes are backported, please check that for the most
up to date information about this issue.


Affected files
==============

The file(s) affected by this issue are:
	include/linux/netdevice.h


Mitigation
==========

The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes.  Individual
changes are never tested alone, but rather are part of a larger kernel
release.  Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all.  If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
	https://git.kernel.org/stable/c/53fd7f912c0877647d6a1e1877f5ea8535ee0b4a
	https://git.kernel.org/stable/c/fa6d98dd925e72fc028b26a0cbbff9d2f0601ff6
	https://git.kernel.org/stable/c/8fc9816404166a90ed8d544dc52482fafffb6d9f
	https://git.kernel.org/stable/c/b0f92a5731dc82556a9ae005cc35f71ab136307b
	https://git.kernel.org/stable/c/99df6b7a713f96eda206680d100b76e15f9d9b69
	https://git.kernel.org/stable/c/74e035f07f53feca09e2352e77fccb09cad5e208
	https://git.kernel.org/stable/c/dbb30dc943a93e083f1e531bfdc6779e57de40d0
	https://git.kernel.org/stable/c/fc902f52a02298c7432b2334c0c82a2885a1a8b6
	https://git.kernel.org/stable/c/3b9a324e646d3657a8d9806dfbfe4f3e4066e882

^ permalink raw reply	[flat|nested] only message in thread

only message in thread, other threads:[~2026-09-03  8:22 UTC | newest]

Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-03  8:22 CVE-2026-80731: net: remove CAP_SYS_RAWIO zero-padding in dev_validate_header Greg Kroah-Hartman

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.