ReviewHigh

CVE-2026-74668

Linux

In the Linux kernel, the following vulnerability has been resolved: packet: use consistent hard_header_len in TX_RING send path tpacket_snd() reads dev->hard_header_len independently for skb allocation and header construction in tpacket_fill_skb(). Concurrent netdevice reconfiguration can therefore make the reserved headroom smaller than the amount later pushed, or make copylen - hard_header_len negative. Snapshot hard_header_len once before processing ring frames and use it for the frame limit, headroom allocation, copy length, and skb construction. Pass the snapshot to tpacket_fill_skb()....

CVSS
7.8
EPSS
-
- percentile
CISA KEV
Not listed
Published
2026.08.23
PRIORITY ASSESSMENT

Review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability-
Technical severityCVSS 7.8

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: packet: use consistent hard_header_len in TX_RING send path tpacket_snd() reads dev->hard_header_len independently for skb allocation and header construction in tpacket_fill_skb(). Concurrent netdevice reconfiguration can therefore make the reserved headroom smaller than the amount later pushed, or make copylen - hard_header_len negative. Snapshot hard_header_len once before processing ring frames and use it for the frame limit, headroom allocation, copy length, and skb construction. Pass the snapshot to tpacket_fill_skb()....

Affected product and versions

Product
Linux
Affected versions
>= 69e3c75f4d541a6eb151b3ef91f34033cb3ad6e1 < 9c7e8ff48c377bef18c3d178748aea0575b69ede, >= 69e3c75f4d541a6eb151b3ef91f34033cb3ad6e1 < 2a73b2c37ee3060a880b53cd24783d93fc7be5f8, >= 69e3c75f4d541a6eb151b3ef91f34033cb3ad6e1 < e79f59a8527a49078cfaf8fe8fb5fcefc20c76d2, >= 69e3c75f4d541a6eb151b3ef91f34033cb3ad6e1 < d85d2fd54e901637c81d847811e03c662aee13cd, >= 69e3c75f4d541a6eb151b3ef91f34033cb3ad6e1 < 016763e829cac37b3234eace86fd0a4c560de4a7, >= 69e3c75f4d541a6eb151b3ef91f34033cb3ad6e1 < 27e068d1b35dbec10a3cf268887c94407be4badc, >= 69e3c75f4d541a6eb151b3ef91f34033cb3ad6e1 < d48ea5c9c4c34dc0df621f0e39ed3a16b644621a, >= 69e3c75f4d541a6eb151b3ef91f34033cb3ad6e1 < 21b5953e7494c16a42e6cd8cf110e18d13ae4a6b, >= 2.6.31
Fixed versions
No verified fixed-version field is available yet

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE
Not available