cbcvebase.
CVE-2026-31700
published 2026-05-01

CVE-2026-31700: In the Linux kernel, the following vulnerability has been resolved: net/packet: fix TOCTOU race on mmap'd vnet_hdr in tpacket_snd() In tpacket_snd(), when…

PriorityP340high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.10%
1.2th percentile
In the Linux kernel, the following vulnerability has been resolved: net/packet: fix TOCTOU race on mmap'd vnet_hdr in tpacket_snd() In tpacket_snd(), when PACKET_VNET_HDR is enabled, vnet_hdr points directly into the mmap'd TX ring buffer shared with userspace. The kernel validates the header via __packet_snd_vnet_parse() but then re-reads all fields later in virtio_net_hdr_to_skb(). A concurrent userspace thread can modify the vnet_hdr fields between validation and use, bypassing all safety checks. The non-TPACKET path (packet_snd()) already correctly copies vnet_hdr to a stack-local variable. All other vnet_hdr consumers in the kernel (tun.c, tap.c, virtio_net.c) also use stack copies. The TPACKET TX path is the only caller of virtio_net_hdr_to_skb() that reads directly from user-controlled shared memory. Fix this by copying vnet_hdr from the mmap'd ring buffer to a stack-local variable before validation and use, consistent with the approach used in packet_snd() and all other callers.

Affected

24 ranges
VendorProductVersion rangeFixed in
linuxlinux
linuxlinux>= 1d036d25e5609ba73fee6a88db01c306b140d512 < 0f4c9754956b86de158a4af5278c5cf5bda9439e0f4c9754956b86de158a4af5278c5cf5bda9439e
linuxlinux>= 1d036d25e5609ba73fee6a88db01c306b140d512 < 714aa973da8163925eda7efd49361ccbee21ee46714aa973da8163925eda7efd49361ccbee21ee46
linuxlinux>= 1d036d25e5609ba73fee6a88db01c306b140d512 < 1490f82353bdabc09265a74e645b07f05cf4188e1490f82353bdabc09265a74e645b07f05cf4188e
linuxlinux>= 1d036d25e5609ba73fee6a88db01c306b140d512 < 74e2db36fe50e3ad9d5300d7fd0e6e2a15a6d12174e2db36fe50e3ad9d5300d7fd0e6e2a15a6d121
linuxlinux>= 1d036d25e5609ba73fee6a88db01c306b140d512 < 3a1bf9116ea31470b89692585c3910dfe830dcdd3a1bf9116ea31470b89692585c3910dfe830dcdd
linuxlinux>= 1d036d25e5609ba73fee6a88db01c306b140d512 < 28324a3b62d9ce7f9bdd65a8ce63f382041d1b2728324a3b62d9ce7f9bdd65a8ce63f382041d1b27
linuxlinux>= 1d036d25e5609ba73fee6a88db01c306b140d512 < 48a6ef291a17639e1b6ae0fbe9c8b2bb87d7804b48a6ef291a17639e1b6ae0fbe9c8b2bb87d7804b
linuxlinux>= 1d036d25e5609ba73fee6a88db01c306b140d512 < 2c054e17d9d41f1020376806c7f750834ced4dc52c054e17d9d41f1020376806c7f750834ced4dc5
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 4.6 < 6.6.1366.6.136
linuxlinux_kernel>= 6.13 < 6.18.256.18.25
linuxlinux_kernel>= 6.19 < 7.0.27.0.2
linuxlinux_kernel>= 6.7 < 6.12.846.12.84
ubuntulinux
ubuntulinux-aws
ubuntulinux-gcp
ubuntulinux-ibm
ubuntulinux-nvidia
ubuntulinux-oracle
ubuntulinux-raspi
ubuntulinux-realtime

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_redhat7.0MEDIUM
vendor_ubuntu2.0LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.