{"cvss":7.8,"datePublished":"2026-05-01T14:16:19.907","dateUpdated":"2026-09-08T09:17:59.693","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/packet: fix TOCTOU race on mmap'd vnet_hdr in tpacket_snd()\n\nIn tpacket_snd(), when PACKET_VNET_HDR is enabled, vnet_hdr points\ndirectly into the mmap'd TX ring buffer shared with userspace. The\nkernel validates the header via __packet_snd_vnet_parse() but then\nre-reads all fields later in virtio_net_hdr_to_skb(). A concurrent\nuserspace thread can modify the vnet_hdr fields between validation\nand use, bypassing all safety checks.\n\nThe non-TPACKET path (packet_snd()) already correctly copies vnet_hdr\nto a stack-local variable. All other vnet_hdr consumers in the kernel\n(tun.c, tap.c, virtio_net.c) also use stack copies. The TPACKET TX\npath is the only caller of virtio_net_hdr_to_skb() that reads directly\nfrom user-controlled shared memory.\n\nFix this by copying vnet_hdr from the mmap'd ring buffer to a\nstack-local variable before validation and use, consistent with the\napproach used in packet_snd() and all other callers.","id":"CVE-2026-31700","raw":{"affected":[{"affectedData":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["net/packet/af_packet.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"0f4c9754956b86de158a4af5278c5cf5bda9439e","status":"affected","version":"1d036d25e5609ba73fee6a88db01c306b140d512","versionType":"git"},{"lessThan":"714aa973da8163925eda7efd49361ccbee21ee46","status":"affected","version":"1d036d25e5609ba73fee6a88db01c306b140d512","versionType":"git"},{"lessThan":"1490f82353bdabc09265a74e645b07f05cf4188e","status":"affected","version":"1d036d25e5609ba73fee6a88db01c306b140d512","versionType":"git"},{"lessThan":"74e2db36fe50e3ad9d5300d7fd0e6e2a15a6d121","status":"affected","version":"1d036d25e5609ba73fee6a88db01c306b140d512","versionType":"git"},{"lessThan":"3a1bf9116ea31470b89692585c3910dfe830dcdd","status":"affected","version":"1d036d25e5609ba73fee6a88db01c306b140d512","versionType":"git"},{"lessThan":"28324a3b62d9ce7f9bdd65a8ce63f382041d1b27","status":"affected","version":"1d036d25e5609ba73fee6a88db01c306b140d512","versionType":"git"},{"lessThan":"48a6ef291a17639e1b6ae0fbe9c8b2bb87d7804b","status":"affected","version":"1d036d25e5609ba73fee6a88db01c306b140d512","versionType":"git"},{"lessThan":"2c054e17d9d41f1020376806c7f750834ced4dc5","status":"affected","version":"1d036d25e5609ba73fee6a88db01c306b140d512","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["net/packet/af_packet.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"4.6"},{"lessThan":"4.6","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"5.10.*","status":"unaffected","version":"5.10.259","versionType":"semver"},{"lessThanOrEqual":"5.15.*","status":"unaffected","version":"5.15.210","versionType":"semver"},{"lessThanOrEqual":"6.1.*","status":"unaffected","version":"6.1.176","versionType":"semver"},{"lessThanOrEqual":"6.6.*","status":"unaffected","version":"6.6.136","versionType":"semver"},{"lessThanOrEqual":"6.12.*","status":"unaffected","version":"6.12.84","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.25","versionType":"semver"},{"lessThanOrEqual":"7.0.*","status":"unaffected","version":"7.0.2","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.1","versionType":"original_commit_for_fix"}]}],"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"affectedData":[{"defaultStatus":"unknown","product":"SIMATIC S7-1500 CPU 1518-4 PN/DP MFP","vendor":"Siemens","versions":[{"lessThan":"*","status":"affected","version":"V3.1.6","versionType":"custom"}]},{"defaultStatus":"unknown","product":"SIMATIC S7-1500 CPU 1518-4 PN/DP MFP","vendor":"Siemens","versions":[{"lessThan":"*","status":"affected","version":"V3.1.6","versionType":"custom"}]},{"defaultStatus":"unknown","product":"SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP","vendor":"Siemens","versions":[{"lessThan":"*","status":"affected","version":"V3.1.6","versionType":"custom"}]},{"defaultStatus":"unknown","product":"SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP","vendor":"Siemens","versions":[{"lessThan":"*","status":"affected","version":"V3.1.6","versionType":"custom"}]},{"defaultStatus":"unknown","product":"SIPLUS S7-1500 CPU 1518-4 PN/DP MFP","vendor":"Siemens","versions":[{"lessThan":"*","status":"affected","version":"V3.1.6","versionType":"custom"}]}],"source":"0b142b55-0307-4c5a-b3c9-f314f3fb7c5e"}],"configurations":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","matchCriteriaId":"7A6CE177-C7BA-4E34-9D61-035565B5FFF5","versionEndExcluding":"6.6.136","versionStartIncluding":"4.6","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","matchCriteriaId":"D4ECA0DE-AFF5-4688-B219-4CA2336CA5B7","versionEndExcluding":"6.12.84","versionStartIncluding":"6.7","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","matchCriteriaId":"8B0A7E0E-F6D8-45DB-8CD9-01839FE40A6C","versionEndExcluding":"6.18.25","versionStartIncluding":"6.13","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","matchCriteriaId":"1BD58F1E-7C20-4C0D-92A2-FAC5CBFBE8A8","versionEndExcluding":"7.0.2","versionStartIncluding":"6.19","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*","matchCriteriaId":"B1EF7059-E670-45F4-B422-54C40FA86390","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:*","matchCriteriaId":"0D38F0BF-A728-4133-A358-D44A2F7EE6D6","vulnerable":true}],"negate":false,"operator":"OR"}]}],"cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/packet: fix TOCTOU race on mmap'd vnet_hdr in tpacket_snd()\n\nIn tpacket_snd(), when PACKET_VNET_HDR is enabled, vnet_hdr points\ndirectly into the mmap'd TX ring buffer shared with userspace. The\nkernel validates the header via __packet_snd_vnet_parse() but then\nre-reads all fields later in virtio_net_hdr_to_skb(). A concurrent\nuserspace thread can modify the vnet_hdr fields between validation\nand use, bypassing all safety checks.\n\nThe non-TPACKET path (packet_snd()) already correctly copies vnet_hdr\nto a stack-local variable. All other vnet_hdr consumers in the kernel\n(tun.c, tap.c, virtio_net.c) also use stack copies. The TPACKET TX\npath is the only caller of virtio_net_hdr_to_skb() that reads directly\nfrom user-controlled shared memory.\n\nFix this by copying vnet_hdr from the mmap'd ring buffer to a\nstack-local variable before validation and use, consistent with the\napproach used in packet_snd() and all other callers."}],"id":"CVE-2026-31700","lastModified":"2026-09-08T09:17:59.693","metrics":{"cvssMetricV31":[{"cvssData":{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"exploitabilityScore":1.8,"impactScore":5.9,"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary"}]},"published":"2026-05-01T14:16:19.907","references":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","url":"https://git.kernel.org/stable/c/0f4c9754956b86de158a4af5278c5cf5bda9439e"},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","url":"https://git.kernel.org/stable/c/1490f82353bdabc09265a74e645b07f05cf4188e"},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":["Patch"],"url":"https://git.kernel.org/stable/c/28324a3b62d9ce7f9bdd65a8ce63f382041d1b27"},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":["Patch"],"url":"https://git.kernel.org/stable/c/2c054e17d9d41f1020376806c7f750834ced4dc5"},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":["Patch"],"url":"https://git.kernel.org/stable/c/3a1bf9116ea31470b89692585c3910dfe830dcdd"},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":["Patch"],"url":"https://git.kernel.org/stable/c/48a6ef291a17639e1b6ae0fbe9c8b2bb87d7804b"},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","url":"https://git.kernel.org/stable/c/714aa973da8163925eda7efd49361ccbee21ee46"},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":["Patch"],"url":"https://git.kernel.org/stable/c/74e2db36fe50e3ad9d5300d7fd0e6e2a15a6d121"},{"source":"0b142b55-0307-4c5a-b3c9-f314f3fb7c5e","url":"https://cert-portal.siemens.com/productcert/html/ssa-019113.html"}],"sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","vulnStatus":"Modified","weaknesses":[{"description":[{"lang":"en","value":"CWE-362"}],"source":"nvd@nist.gov","type":"Primary"}]},"severity":"HIGH","source":"nvd","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/packet: fix TOCTOU race on mmap'd vnet_hdr i..."}