From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 78F0643BDC8 for ; Thu, 3 Sep 2026 08:22:33 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788423754; cv=none; b=YqMxWHqXZ84b8T/+go7GZOvWCILRlNQ8jdbv/hLTSb+GDjOvEHy81MF18O/UNRo6CFAvzDjhgAN7g6MiFs2GbgXfzrMJXqrhk1rBwPlEKYS2v9Ij/COnxhIR77ugVbjNfHjvDiFpGragjlyfaFNDrV13wXvC2qauGUp7cWef+So= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788423754; c=relaxed/simple; bh=CtGXsXiGXZ9MT41X2SVocwfpYhsEVF+7VG8LSkm8DTA=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=dpe/kwjvqki5rgYU1zsxacV2lV8Pt9kq+8GErBztl48GpiCdkWHYdtML15QYIjEQe6N0l+YmTfpFX/2ksnp4E6t1BW7UPXwpmt44oGaOPF3rGsyH+sJl1NumSYxAxd1AAZQomjj9TCcNmN//YWDSBP5txjnl+qYEJrYiHkbSuIY= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=WxHsRwKh; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="WxHsRwKh" Received: by smtp.kernel.org (Postfix) with ESMTPSA id D43AD1F000E9; Thu, 3 Sep 2026 08:22:32 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1788423753; bh=UiU1ANPrYcAdzKRijziOXkxvynnN1V2ICccYOzowPnQ=; h=From:To:Cc:Subject:Date:Reply-To; b=WxHsRwKh4pWo90TmxBDkem7iwDKG212PxTRRE+lABih/xdNnpaahZGfYhAHOnQZez h8nB3gf642ZTbpGFqLw6XKRgRpFXeea9Si8r+pWxWLI2NssfAmqLuSsMT2UNLblXR+ V7zFg38Rv6AjS/4GmuyBvmWDPSdhdo8y0tKMqFSg= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-80731: net: remove CAP_SYS_RAWIO zero-padding in dev_validate_header Date: Thu, 3 Sep 2026 10:22:00 +0200 Message-ID: <2026090358-CVE-2026-80731-49e3@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=5096; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=QPyGESd0H/COI8lu0WuO2bs1p6epS5siv1vvxB8UAVQ=; b=owGbwMvMwCRo6H6F97bub03G02pJDFkz9dQ2/yufbBNxhSWhUuXFqrez7mjv3czeF9ApMc2JZ du5ugNJHbEsDIJMDLJiiixftvEc3V9xSNHL0PY0zBxWJpAhDFycAjARvxaGecpLt27WeR4349t+ /cb2P69enWNfcoVhvmd23YaICp8ZRZtvc2scLItp3j1zKwA= X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: net: remove CAP_SYS_RAWIO zero-padding in dev_validate_header dev_validate_header() reads dev->hard_header_len directly when zero-padding short link layer headers for CAP_SYS_RAWIO holders: if (capable(CAP_SYS_RAWIO)) { memset(ll_header + len, 0, dev->hard_header_len - len); return true; } Packet send paths call dev_validate_header() on skbs whose headroom was allocated from an earlier hard_header_len read. If the device is reconfigured so that dev->hard_header_len increases before validation, the memset writes past the reserved buffer, an out-of-bounds write. This out-of-bounds write is masked in some SOCK_RAW paths today because the same concurrent increase can first make skb_push() exceed the reserved headroom and trigger skb_under_panic(). Remove the zero-padding branch before making those hard_header_len reads consistent, so the snapshot fixes do not turn a loud panic into a silent overwrite. This path is only reached for variable length L2 protocols, where len < hard_header_len but len >= min_header_len. No remaining in-tree variable length L2 protocol implements header_ops->validate, and the CAP_SYS_RAWIO bypass that zero-pads and accepts short headers has no real value beyond allowing testing of intentionally malformed input. Drop the CAP_SYS_RAWIO branch. The remaining reads of dev->hard_header_len in dev_validate_header() are comparisons only and have no memory safety impact. The Linux kernel CVE team has assigned CVE-2026-80731 to this issue. Affected and fixed versions =========================== Issue introduced in 3.2.80 with commit b5518429e70cd783b8ca52335456172c1a0589f6 and fixed in 3.2.81 with commit 53fd7f912c0877647d6a1e1877f5ea8535ee0b4a Issue introduced in 4.6 with commit 2793a23aacbd754dbbb5cb75093deb7e4103bace and fixed in 5.10.265 with commit fa6d98dd925e72fc028b26a0cbbff9d2f0601ff6 Issue introduced in 4.6 with commit 2793a23aacbd754dbbb5cb75093deb7e4103bace and fixed in 5.15.216 with commit 8fc9816404166a90ed8d544dc52482fafffb6d9f Issue introduced in 4.6 with commit 2793a23aacbd754dbbb5cb75093deb7e4103bace and fixed in 6.1.183 with commit b0f92a5731dc82556a9ae005cc35f71ab136307b Issue introduced in 4.6 with commit 2793a23aacbd754dbbb5cb75093deb7e4103bace and fixed in 6.6.152 with commit 99df6b7a713f96eda206680d100b76e15f9d9b69 Issue introduced in 4.6 with commit 2793a23aacbd754dbbb5cb75093deb7e4103bace and fixed in 6.12.104 with commit 74e035f07f53feca09e2352e77fccb09cad5e208 Issue introduced in 4.6 with commit 2793a23aacbd754dbbb5cb75093deb7e4103bace and fixed in 6.18.45 with commit dbb30dc943a93e083f1e531bfdc6779e57de40d0 Issue introduced in 4.6 with commit 2793a23aacbd754dbbb5cb75093deb7e4103bace and fixed in 7.1.9 with commit fc902f52a02298c7432b2334c0c82a2885a1a8b6 Issue introduced in 4.6 with commit 2793a23aacbd754dbbb5cb75093deb7e4103bace and fixed in 7.2 with commit 3b9a324e646d3657a8d9806dfbfe4f3e4066e882 Issue introduced in 3.16.36 with commit f58a6c08ebdfa978178bbca78c2ba744a2665912 Issue introduced in 4.1.28 with commit 1df16498dfd0d5a129bdf2982d9a08df73e8923d Issue introduced in 4.4.8 with commit 8b8d278aa4de9335682bbd4a3bb619af015c859e Issue introduced in 4.5.2 with commit 6804052fa9d86e9a512c88b24a5debbfc1a490fc Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-80731 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: include/linux/netdevice.h Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/53fd7f912c0877647d6a1e1877f5ea8535ee0b4a https://git.kernel.org/stable/c/fa6d98dd925e72fc028b26a0cbbff9d2f0601ff6 https://git.kernel.org/stable/c/8fc9816404166a90ed8d544dc52482fafffb6d9f https://git.kernel.org/stable/c/b0f92a5731dc82556a9ae005cc35f71ab136307b https://git.kernel.org/stable/c/99df6b7a713f96eda206680d100b76e15f9d9b69 https://git.kernel.org/stable/c/74e035f07f53feca09e2352e77fccb09cad5e208 https://git.kernel.org/stable/c/dbb30dc943a93e083f1e531bfdc6779e57de40d0 https://git.kernel.org/stable/c/fc902f52a02298c7432b2334c0c82a2885a1a8b6 https://git.kernel.org/stable/c/3b9a324e646d3657a8d9806dfbfe4f3e4066e882