drivers/net/bonding/bond_main.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-)
From: Xiang Mei <xmei5@asu.edu>
Please queue the attached backport of upstream commit 2884bf72fb8f. It fixes
CVE-2026-31419 in 6.1.y.
An unprivileged user can create a broadcast bond and dummy slaves in a user
and network namespace. Racing ordinary packet sends with slave release makes
`bond_xmit_broadcast()` give the same skb to two transmitters. I reproduced a
KASAN use-after-free in `skb_clone()` on v6.1.182.
The attached one-line upstream fix applies cleanly to v6.1.182. The same
workload completed over one million sends and 299 slave mutations with the
patched module and no sanitizer, oops, lock, or BUG output.
The fix is already released in 6.6.143, 6.12.95, 6.18.22, and 6.19.12, but no
corresponding fix is present in 6.1.y.
Signed-off-by: Artem Dinaburg <artem@trailofbits.com>
---
drivers/net/bonding/bond_main.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/net/bonding/bond_main.c b/drivers/net/bonding/bond_main.c
index 9898d85075d150..4370ba922b2cc2 100644
--- a/drivers/net/bonding/bond_main.c
+++ b/drivers/net/bonding/bond_main.c
@@ -5344,7 +5344,7 @@ static netdev_tx_t bond_xmit_broadcast(struct sk_buff *skb,
if (!(bond_slave_is_up(slave) && slave->link == BOND_LINK_UP))
continue;
- if (bond_is_last_slave(bond, slave)) {
+ if (i + 1 == slaves_count) {
skb2 = skb;
skb_used = true;
} else {
--
2.39.5
On Wed, Aug 19, 2026 at 12:59:22PM -0400, Artem Dinaburg wrote: > From: Xiang Mei <xmei5@asu.edu> > > Please queue the attached backport of upstream commit 2884bf72fb8f. It fixes > CVE-2026-31419 in 6.1.y. > > An unprivileged user can create a broadcast bond and dummy slaves in a user > and network namespace. Racing ordinary packet sends with slave release makes > `bond_xmit_broadcast()` give the same skb to two transmitters. I reproduced a > KASAN use-after-free in `skb_clone()` on v6.1.182. > > The attached one-line upstream fix applies cleanly to v6.1.182. The same > workload completed over one million sends and 299 slave mutations with the > patched module and no sanitizer, oops, lock, or BUG output. > > The fix is already released in 6.6.143, 6.12.95, 6.18.22, and 6.19.12, but no > corresponding fix is present in 6.1.y. > > Signed-off-by: Artem Dinaburg <artem@trailofbits.com> You stripped off all of the original commit changelog info :( thanks, greg k-h
© 2016 - 2026 Red Hat, Inc.