In the Linux kernel, the following vulnerability has been resolved:
net/packet: reset the MAC header on the packet-socket transmit path
packet_parse_headers() resets the MAC header only for a SOCK_RAW frame whose socket did not bind a protocol. A protocol-bound SOCK_RAW socket, any SOCK_DGRAM frame, and the legacy SOCK_PACKET path therefore leave skb->mac_header unset here.
For frames sent via __dev_queue_xmit() this is harmless: it resets the MAC header unconditionally. But the packet-socket PACKET_QDISC_BYPASS path uses dev_direct_xmit(), which does not, so the frame reaches ndo_start_xmit() with the MAC header unset. A driver that reads eth_hdr(skb) on transmit then dereferences skb->head + (u16)~0, an out-of-bounds access ~64 KiB past the head -- the same class fixed for one consumer in commit f5089008f90c ("macsec: do not read an unset MAC header in macsec_encrypt()").
packet_parse_headers() runs only on the transmit path, where skb->data points at the start of the L2 header for every packet-socket type regardless of its length: SOCK_RAW and SOCK_PACKET carry a user-supplied header and SOCK_DGRAM has one built by dev_hard_header(). Reset the MAC header unconditionally, mirroring __dev_queue_xmit(), so the frame is anchored on the bypass path too.
Found by 0sec (https://0sec.ai) using automated source analysis; verified against source and matched to the macsec KASAN report in f5089008f90c. Compile-tested.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux_2023 | — | Upgrade kernel6.18Upgrade kernel6.18-debuginfoUpgrade kernel6.18-debuginfo-common-aarch64Upgrade kernel6.18-debuginfo-common-x86_64Upgrade kernel6.18-headersUpgrade kernel-livepatch-6.18.48-107.148Upgrade kernel6.18-develUpgrade python3-perf6.18Upgrade bpftool6.18-debuginfoUpgrade kernel6.18-toolsUpgrade perf6.18Upgrade kernel6.18-tools-develUpgrade kernel6.18-modules-extra-commonUpgrade kernel6.18-tools-debuginfoUpgrade python3-perf6.18-debuginfoUpgrade bpftool6.18Upgrade perf6.18-debuginfoUpgrade kernel6.18-modules-extraUpgrade microvm-kernel6.18 | Sep 30, 2026 | Aug 22, 2026 |
| Debian | — | Upgrade linuxUpgrade linux-6.12 | Aug 26, 2026 | Aug 26, 2026 |
| Redhat_linux | — | No solution exists | Aug 26, 2026 | Aug 22, 2026 |
| Ubuntu | — | Upgrade linux-image-intel-iot-realtime-5.15Upgrade linux-image-azure-cvmUpgrade linux-image-oracleUpgrade linux-image-azure-fdeUpgrade linux-image-realtimeUpgrade linux-image-virtual-5.15Upgrade linux-image-generic-lpaeUpgrade linux-image-azure-fde-5.15Upgrade linux-image-aws-fips-5.15Upgrade linux-image-aws-64k-5.15Upgrade linux-image-awsUpgrade linux-image-5.15.0-1080-xilinx-zynqmpUpgrade linux-image-lowlatency-64k-5.15Upgrade linux-image-gcp-lts-22.04Upgrade linux-image-gcp-fips-5.15Upgrade linux-image-kvmUpgrade linux-image-generic-5.15Upgrade linux-image-xilinx-zynqmp-5.15Upgrade linux-image-generic-64k-hwe-20.04Upgrade linux-image-generic-64k-5.15Upgrade linux-image-5.15.0-1117-awsUpgrade linux-image-5.15.0-1111-ibmUpgrade linux-image-virtualUpgrade linux-image-ibm-5.15Upgrade linux-image-aws-5.15Upgrade linux-image-oracle-lts-22.04Upgrade linux-image-fipsUpgrade linux-image-5.15.0-198-generic-64kUpgrade linux-image-5.15.0-1100-gkeopUpgrade linux-image-gcp-5.15Upgrade linux-image-aws-lts-22.04Upgrade linux-image-5.15.0-195-lowlatencyUpgrade linux-image-5.15.0-1109-kvmUpgrade linux-image-azure-fipsUpgrade linux-image-generic-lpae-hwe-20.04Upgrade linux-image-aws-fipsUpgrade linux-image-5.15.0-1123-azure-fipsUpgrade linux-image-lowlatency-64k-hwe-20.04Upgrade linux-image-gkeop-5.15Upgrade linux-image-5.15.0-198-genericUpgrade linux-image-oem-20.04Upgrade linux-image-gcpUpgrade linux-image-azure-fips-5.15Upgrade linux-image-generic-lpae-5.15Upgrade linux-image-generic-64kUpgrade linux-image-5.15.0-1109-intel-iot-realtimeUpgrade linux-image-kvm-5.15Upgrade linux-image-intel-iotgUpgrade linux-image-virtual-hwe-20.04Upgrade linux-image-gcp-fipsUpgrade linux-image-intel-iotg-5.15Upgrade linux-image-intelUpgrade linux-image-gkeopUpgrade linux-image-generic-hwe-20.04Upgrade linux-image-genericUpgrade linux-image-5.15.0-195-lowlatency-64kUpgrade linux-image-5.15.0-1116-realtimeUpgrade linux-image-xilinx-zynqmpUpgrade linux-image-ibmUpgrade linux-image-gkeUpgrade linux-image-lowlatency-5.15Upgrade linux-image-oem-20.04dUpgrade linux-image-oem-20.04cUpgrade linux-image-azure-lts-22.04Upgrade linux-image-5.15.0-1122-azure-fdeUpgrade linux-image-oracle-5.15Upgrade linux-image-5.15.0-198-fipsUpgrade linux-image-5.15.0-1118-gcpUpgrade linux-image-5.15.0-1117-aws-64kUpgrade linux-image-aws-64k-lts-22.04Upgrade linux-image-5.15.0-1114-oracleUpgrade linux-image-5.15.0-1123-azureUpgrade linux-image-5.15.0-1118-gcp-fipsUpgrade linux-image-5.15.0-1117-aws-fipsUpgrade linux-image-lowlatencyUpgrade linux-image-azure-5.15Upgrade linux-image-5.15.0-198-generic-lpaeUpgrade linux-image-5.15.0-1112-intel-iotgUpgrade linux-image-realtime-5.15Upgrade linux-image-gke-5.15Upgrade linux-image-5.15.0-1113-gkeUpgrade linux-image-intel-iot-realtimeUpgrade linux-image-fips-5.15Upgrade linux-image-azureUpgrade linux-image-oem-20.04bUpgrade linux-image-lowlatency-hwe-20.04Upgrade linux-image-lowlatency-64k | Oct 6, 2026 | Oct 6, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Sep 15, 2026 | Aug 22, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub