High [CVE-2026-74582] use consistent hard_header_len in non-ring send paths
This high-severity Red Hat Linux advisory covers CVE-2026-74582 affecting Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On.
Aggregated and source-linked by VulniPulse. Data sources, validation and limitations.
VulniPulse record published Record updated
Android app · Google Play
Monitor future Red Hat Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.
Summary
In the Linux kernel, the following vulnerability has been resolved: packet: use consistent hard_header_len in non-ring send paths packet_snd() reads dev->hard_header_len multiple times while allocating and constructing an skb. Device reconfiguration can change this value concurrently, for example through bonding device type changes.
For SOCK_RAW, packet_snd() can save a larger value in reserve and later allocate headroom using a smaller value.
Moving skb->data back by reserve then places it before skb->head, and the following copy from userspace can attempt an out-of-bounds write. packet_sendmsg_spkt() has the same issue because it calculates its reservation and header offset from separate reads before dropping the RCU read lock to allocate the skb.
Add LL_RESERVED_SPACE_EX() for callers that already saved a header length. Read hard_header_len once in packet_snd() and use it for allocation and construction.
In packet_sendmsg_spkt(), preserve the allocation-time value through the device lookup retry. The separate SOCK_DGRAM consistency problem between hard_header_len and header_ops->create is not addressed here.
An out-of-bounds write problem was observed in packet_sendmsg_spkt in net/packet/af_packet.c in the Linux Kernel. In this flaw, AF_PACKET hard_header_len race may allow local privilege escalation.
Affected versions
No affected-version range was extracted from the source record. The vendor advisory is authoritative — check it before change work.
Official advisory · high-confidence parse· fetched 13 days ago·verify at source
- kernel-0:6.12.0-55.102.1.el10_0
- kernel-0:4.18.0-305.206.1.el8_4
- kernel-0:4.18.0-372.213.1.el8_6
- kernel-0:4.18.0-477.165.1.el8_8
- kernel-0:5.14.0-284.191.1.el9_2
- kernel-rt-0:5.14.0-284.191.1.rt14.476.el9_2
- kernel-0:5.14.0-427.147.1.el9_4
- kernel-0:5.14.0-570.136.1.el9_6
- RHSA-2026:62609
- RHSA-2026:65710
- RHSA-2026:65711
- RHSA-2026:63537
- RHSA-2026:67723
- RHSA-2026:67721
- RHSA-2026:60484
- RHSA-2026:60486
Official advisory · high-confidence parse· fetched 13 days ago·verify at source
Mitigation
Upgrade to a fixed release: kernel-0:6.12.0-55.102.1.el10_0, kernel-0:4.18.0-305.206.1.el8_4, kernel-0:4.18.0-372.213.1.el8_6, kernel-0:4.18.0-477.165.1.el8_8, kernel-0:5.14.0-284.191.1.el9_2, kernel-rt-0:5.14.0-284.191.1.rt14.476.el9_2. That is the remediation for this advisory.
The vendor advisory may list additional interim mitigations or workarounds not captured here — review it before change work.
Official advisory · high-confidence parse· fetched 13 days ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.