HIGH
packet RxRing Leak
CVE-2026-98233
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
01Description
In the Linux kernel, the following vulnerability has been resolved: net/packet: clear RX owner on VNET header error Commit 61fad6816fc1 ("net/packet: tpacket_rcv: avoid a producer race condition") added rx_owner_map and made tpacket_rcv() claim a V1 or V2 ring slot before converting the virtio-net header. If the conversion fails, the drop path leaves the slot claimed. With a one-frame TPACKET_V2 ring, an unsupported UDP GSO packet leaves the only slot unavailable, so the ring also drops the next valid packet. Clear the ownership bit on this error path. TPACKET_V3 already clears its block state here.
02KernelScan AI Analysis
Risk summary
A remote or local attacker can deny service to applications using packet socket rings with virtio-net header support by sending packets that trigger a virtio-net header conversion error. Each failed conversion permanently leaks a ring slot; once all slots are consumed, the ring drops all subsequent packets, rendering the monitoring application blind. The impact is limited to availability of the affected packet socket — there is no memory corruption or information disclosure.
Vulnerability analysis
When a packet is received on a socket configured with a packet receive ring and virtio-net header support, the kernel claims a ring slot to prevent concurrent writers from reusing it, then attempts to convert the packet's virtio-net header. If that conversion fails (for example, for an unsupported UDP GSO packet), the error-drop path releases the packet but leaves the slot's ownership bit set. With a small ring, leaked slots quickly accumulate until no slots remain available, causing the ring to drop every subsequent valid packet and denying service to the monitoring application. The fix clears the ownership bit for TPACKET_V1/V2 rings on this error path, matching the cleanup that TPACKET_V3 already performs. The bug is triggered by receiving certain packets on a packet socket with virtio-net header enabled; a remote attacker can send such packets to the host over the network, or a local user can send UDP GSO packets to the loopback interface, with no special privileges required on the attacker's side.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| 4.14 | 4.14.175 | 4.15 | bb10a0084c03 |
| 4.19 | 4.19.114 | 4.20 | b8c0cb306905 |
| 5.4 | 5.4.29 | 5.5 | 2daa618e7ff1 |
| 5.5 | 5.5.14 | 5.6 | 23cd30498891 |
| 5.10 | — | 5.10.271 | 49a48a5aaf85 |
| 5.15 | — | 5.15.222 | 805edbdcb868 |
| 6.1 | — | 6.1.189 | 693209a237fc |
| 6.6 | — | 6.6.158 | 33ff111d7ba3 |
| 6.12 | — | 6.12.112 | — |
| 6.18 | — | 6.18.54 | — |
| 7.2 | — | 7.2.8 | — |
| mainline | — | 7.3-rc4 | — |