7.5

CVE-2026-64545

net, bpf: check master for NULL in xdp_master_redirect()

In the Linux kernel, the following vulnerability has been resolved:

net, bpf: check master for NULL in xdp_master_redirect()

xdp_master_redirect() dereferences the result of
netdev_master_upper_dev_get_rcu() without a NULL check, but that helper
returns NULL when the receiving device has no upper-master adjacency.

The reach guard only checks netif_is_bond_slave(). On bond slave release
bond_upper_dev_unlink() drops the upper-master adjacency before clearing
IFF_SLAVE, so an XDP_TX reaching xdp_master_redirect() in that window
still passes netif_is_bond_slave() while master is already NULL, and
faults on master->flags at offset 0xb0:

  BUG: kernel NULL pointer dereference, address: 00000000000000b0
  RIP: 0010:xdp_master_redirect (net/core/filter.c:4432)
  Call Trace:
   xdp_master_redirect (net/core/filter.c:4432)
   bpf_prog_run_generic_xdp (include/net/xdp.h:700)
   do_xdp_generic (net/core/dev.c:5608)
   __netif_receive_skb_one_core (net/core/dev.c:6204)
   process_backlog (net/core/dev.c:6319)
   __napi_poll (net/core/dev.c:7729)
   net_rx_action (net/core/dev.c:7792)
   handle_softirqs (kernel/softirq.c:622)
   __dev_queue_xmit (include/linux/bottom_half.h:33)
   packet_sendmsg (net/packet/af_packet.c:3082)
   __sys_sendto (net/socket.c:2252)
  Kernel panic - not syncing: Fatal exception in interrupt

The missing check dates back to the original code; commit 1921f91298d1
("net, bpf: fix null-ptr-deref in xdp_master_redirect() for down master")
later added the master->flags read where the fault now lands but kept the
unconditional deref. Check master for NULL before use; a NULL master is
treated the same as one that is not up.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version 879af96ffd72706c6e3278ea6b45b0b0e37ec5d7
Version < c99ca049e910d61ddbd28cc2c47242f2bfbb4970
Status affected
Version 879af96ffd72706c6e3278ea6b45b0b0e37ec5d7
Version < e2a56441233131fe18a76001de347ecda217e40c
Status affected
Version 879af96ffd72706c6e3278ea6b45b0b0e37ec5d7
Version < 3876318ea54e83eb70982b8280a3c5e4e32269bf
Status affected
Version 879af96ffd72706c6e3278ea6b45b0b0e37ec5d7
Version < 4edbcacca09f92b85d3951b6add11894b20a84bc
Status affected
Version 879af96ffd72706c6e3278ea6b45b0b0e37ec5d7
Version < 03b743586a2469744e96e9c1015096d07240935d
Status affected
Version 879af96ffd72706c6e3278ea6b45b0b0e37ec5d7
Version < 89c103d702b25ceb2d097faf854deb47b53b17ff
Status affected
Version 879af96ffd72706c6e3278ea6b45b0b0e37ec5d7
Version < e82d8cc4321c373dc46e741cd2dfdaa7921fddb7
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 5.15
Status affected
Version 0
Version < 5.15
Status unaffected
Version <= 5.15.*
Version 5.15.212
Status unaffected
Version <= 6.1.*
Version 6.1.178
Status unaffected
Version <= 6.6.*
Version 6.6.145
Status unaffected
Version <= 6.12.*
Version 6.12.97
Status unaffected
Version <= 6.18.*
Version 6.18.40
Status unaffected
Version <= 7.1.*
Version 7.1.5
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.5% 0.398
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/c99ca049e910d61ddbd28cc2c47242f2bfbb4970
https://git.kernel.org/stable/c/e2a56441233131fe18a76001de347ecda217e40c
https://git.kernel.org/stable/c/3876318ea54e83eb70982b8280a3c5e4e32269bf
https://git.kernel.org/stable/c/4edbcacca09f92b85d3951b6add11894b20a84bc
https://git.kernel.org/stable/c/03b743586a2469744e96e9c1015096d07240935d
https://git.kernel.org/stable/c/89c103d702b25ceb2d097faf854deb47b53b17ff
https://git.kernel.org/stable/c/e82d8cc4321c373dc46e741cd2dfdaa7921fddb7