In the Linux kernel, the following vulnerability has been resolved:
packet: synchronize pressure clearing with ring reconfiguration
packet_set_ring() updates the RX ring state under sk_receive_queue.lock, but used to publish the tpacket receive mode through po->prot_hook.func after releasing that lock. packet_poll() and packet_recvmsg() can then run the pressure clearing path after the ring has been cleared while still seeing tpacket_rcv, causing __packet_rcv_has_room() to dereference stale or NULL ring storage.
Move the existing receive hook assignment into the same sk_receive_queue.lock section as the ring state update. Keep the assignment otherwise unchanged, including on TX ring reconfiguration, to avoid adding behavior changes that are not required for the fix.
Serialize packet_recvmsg() pressure clearing with the same queue lock only after PACKET_SOCK_PRESSURE has been observed. If the flag is clear and the socket has moved away from tpacket_rcv, packet_set_ring() has already detached the socket and waited for synchronize_net(), so no new packet input can set the flag again.
packet_poll() already holds sk_receive_queue.lock, so it uses the new unlocked helper directly.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux_2023 | — | Upgrade perf6.18-debuginfoUpgrade kernel-livepatch-6.18.48-107.148Upgrade kernel6.18-toolsUpgrade kernel6.18-debuginfoUpgrade kernel6.18-tools-develUpgrade kernel6.18-modules-extraUpgrade bpftool6.18-debuginfoUpgrade kernel6.18-develUpgrade kernel6.18-debuginfo-common-x86_64Upgrade kernel6.18-headersUpgrade microvm-kernel6.18Upgrade kernel6.18-debuginfo-common-aarch64Upgrade kernel6.18Upgrade python3-perf6.18Upgrade kernel6.18-modules-extra-commonUpgrade bpftool6.18Upgrade python3-perf6.18-debuginfoUpgrade perf6.18Upgrade kernel6.18-tools-debuginfo | Sep 30, 2026 | Aug 22, 2026 |
| Debian | — | Upgrade linuxUpgrade linux-6.12 | Aug 26, 2026 | Aug 26, 2026 |
| Redhat_linux | — | No solution exists | Aug 25, 2026 | Aug 22, 2026 |
| Ubuntu | — | Upgrade linux-image-nvidia-tegra-6.8Upgrade linux-image-6.8.0-1036-nvidia-tegraUpgrade linux-image-nvidia-tegra-rtUpgrade linux-image-6.8.0-1036-nvidia-tegra-rtUpgrade linux-image-nvidia-tegra-rt-6.8Upgrade linux-image-nvidia-tegra | Oct 7, 2026 | Oct 6, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Sep 15, 2026 | Aug 22, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub