-
CVE-2026-74684
- EPSS 0.17%
- Veröffentlicht 22.08.2026 16:16:42
- Zuletzt bearbeitet 23.08.2026 13:16:48
- CVE-Watchlists
- Unerledigt
net: tap: set skb->dev before parsing virtio net header in tap_get_user_xdp()
In the Linux kernel, the following vulnerability has been resolved:
net: tap: set skb->dev before parsing virtio net header in tap_get_user_xdp()
The commit 4f61f133f354 ("net: tap: NULL pointer derefence in
dev_parse_header_protocol when skb->dev is null") fixed a crash in
tap_get_user() by assigning skb->dev before calling tun_vnet_hdr_to_skb().
This is required because virtio_net_hdr_to_skb() may invoke
dev_parse_header_protocol(), which dereferences skb->dev. Without the
assignment, a NULL pointer dereference can occur.
However, tap_get_user_xdp() still parses the virtio-net header before
assigning skb->dev. When the vhost TX path passes an XDP buffer containing
a GSO virtio-net header but the protocol is set to zero on purpose,
tun_vnet_hdr_to_skb() can reach dev_parse_header_protocol() while skb->dev
is still NULL, resulting in a crash.
Fix this by looking up the tap device and assigning skb->dev before calling
tun_vnet_hdr_to_skb(), matching the ordering already used in
tap_get_user(). Preserve the existing RCU read-side critical section across
dev_queue_xmit().Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
924a9bc362a5223cd448ca08c3dde21235adc310
Version <
15583b07fd691a844fbf7b3ad612cdc9e9a657c0
Status
affected
Version
924a9bc362a5223cd448ca08c3dde21235adc310
Version <
8b444b126cd8e4473e652f529753ed4dd1360a9c
Status
affected
Version
924a9bc362a5223cd448ca08c3dde21235adc310
Version <
164c31ee252ebd1ac8f44c2dfc5486b6d9a0379b
Status
affected
Version
924a9bc362a5223cd448ca08c3dde21235adc310
Version <
3874892dd27d5387aa9a06f58d9060f18f351d24
Status
affected
Version
ea3fb2ce5fa794d02135f5c079e05cd6fc3f545d
Status
affected
Version
54ef8243c3c8e90f1ea5792e6752e021a25c8eb3
Status
affected
Version
ca278267d6cd9544645731732455b6b20cb0e895
Status
affected
Version
faa3baa2828c5e1c4374f3e60041f75c64f5fcb6
Status
affected
Version
99b1d3f74b9ef72c2f74c8e4c078e1bc0706e748
Status
affected
Version
4.14.226
Version <
4.15
Status
affected
Version
4.19.181
Version <
4.20
Status
affected
Version
5.4.106
Version <
5.5
Status
affected
Version
5.10.24
Version <
5.11
Status
affected
Version
5.11.7
Version <
5.12
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
5.12
Status
affected
Version
0
Version <
5.12
Status
unaffected
Version <=
6.12.*
Version
6.12.105
Status
unaffected
Version <=
6.18.*
Version
6.18.45
Status
unaffected
Version <=
7.1.*
Version
7.1.9
Status
unaffected
Version <=
*
Version
7.2
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.17% | 0.062 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|
https://git.kernel.org/stable/c/15583b07fd691a844fbf7b3ad612cdc9e9a657c0
https://git.kernel.org/stable/c/164c31ee252ebd1ac8f44c2dfc5486b6d9a0379b
https://git.kernel.org/stable/c/3874892dd27d5387aa9a06f58d9060f18f351d24
https://git.kernel.org/stable/c/8b444b126cd8e4473e652f529753ed4dd1360a9c