7.8

CVE-2026-68338

net/packet: avoid fanout hook re-registration after unregister

In the Linux kernel, the following vulnerability has been resolved:

net/packet: avoid fanout hook re-registration after unregister

packet_set_ring() temporarily detaches a socket from packet delivery while
reconfiguring its ring. It records the previous running state, clears
po->num, unregisters the protocol hook when needed, drops po->bind_lock,
and later restores po->num and re-registers the hook from the saved
was_running value.

That unlocked window can race with NETDEV_UNREGISTER. The notifier can
observe the socket as not running, skip __unregister_prot_hook(), and
invalidate the per-socket binding by setting po->ifindex to -1 and clearing
po->prot_hook.dev. A one-member fanout group can still retain its shared
fanout hook device pointer. When packet_set_ring() resumes, re-registering
solely from the stale was_running state can re-add the fanout hook after
the device has been unregistered.

Treat po->ifindex == -1 as an invalidated binding after reacquiring
po->bind_lock. This is distinct from ifindex 0, the normal
unbound/wildcard state: ifindex -1 marks an existing device binding that
was invalidated when the device was unregistered. Restore po->num as
before, but do not re-register the hook if device unregister already
detached the socket.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version dc99f600698dcac69b8f56dda9a8a00d645c5ffc
Version < acb40ebfa5c4d62f84339fcbf713f2a9fd033a71
Status affected
Version dc99f600698dcac69b8f56dda9a8a00d645c5ffc
Version < c820f4b7f2fa38f8769db0d0cefdd94e2721504d
Status affected
Version dc99f600698dcac69b8f56dda9a8a00d645c5ffc
Version < 4628efbdc7affd094181f5263e65c1062e31f15f
Status affected
Version dc99f600698dcac69b8f56dda9a8a00d645c5ffc
Version < 80ec024d53a05c60ad1d08968dcf745f10c1665c
Status affected
Version dc99f600698dcac69b8f56dda9a8a00d645c5ffc
Version < 0a052e0808e015e68144a9877e6ef42b952c49fa
Status affected
Version dc99f600698dcac69b8f56dda9a8a00d645c5ffc
Version < 1bc55c29cd85818e9052f17deb287d5a11fb817f
Status affected
Version dc99f600698dcac69b8f56dda9a8a00d645c5ffc
Version < a885387dae7986a55bae5c77a15bdd447f64e9b9
Status affected
Version dc99f600698dcac69b8f56dda9a8a00d645c5ffc
Version < 50aff80475abd3533eef4320477037e6fcc6b56e
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 3.1
Status affected
Version 0
Version < 3.1
Status unaffected
Version <= 5.10.*
Version 5.10.265
Status unaffected
Version <= 5.15.*
Version 5.15.216
Status unaffected
Version <= 6.1.*
Version 6.1.183
Status unaffected
Version <= 6.6.*
Version 6.6.148
Status unaffected
Version <= 6.12.*
Version 6.12.101
Status unaffected
Version <= 6.18.*
Version 6.18.42
Status unaffected
Version <= 7.1.*
Version 7.1.6
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.18% 0.074
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/80ec024d53a05c60ad1d08968dcf745f10c1665c
https://git.kernel.org/stable/c/0a052e0808e015e68144a9877e6ef42b952c49fa
https://git.kernel.org/stable/c/1bc55c29cd85818e9052f17deb287d5a11fb817f
https://git.kernel.org/stable/c/a885387dae7986a55bae5c77a15bdd447f64e9b9
https://git.kernel.org/stable/c/50aff80475abd3533eef4320477037e6fcc6b56e
https://git.kernel.org/stable/c/4628efbdc7affd094181f5263e65c1062e31f15f
https://git.kernel.org/stable/c/acb40ebfa5c4d62f84339fcbf713f2a9fd033a71
https://git.kernel.org/stable/c/c820f4b7f2fa38f8769db0d0cefdd94e2721504d