Home

Description

In the Linux kernel, the following vulnerability has been resolved: team: fix header_ops type confusion with non-Ethernet ports Similar to commit 950803f72547 ("bonding: fix type confusion in bond_setup_by_slave()") team has the same class of header_ops type confusion. For non-Ethernet ports, team_setup_by_port() copies port_dev->header_ops directly. When the team device later calls dev_hard_header() or dev_parse_header(), these callbacks can run with the team net_device instead of the real lower device, so netdev_priv(dev) is interpreted as the wrong private type and can crash. The syzbot report shows a crash in bond_header_create(), but the root cause is in team: the topology is gre -> bond -> team, and team calls the inherited header_ops with its own net_device instead of the lower device, so bond_header_create() receives a team device and interprets netdev_priv() as bonding private data, causing a type confusion crash. Fix this by introducing team header_ops wrappers for create/parse, selecting a team port under RCU, and calling the lower device callbacks with port->dev, so each callback always sees the correct net_device context. Also pass the selected lower device to the lower parse callback, so recursion is bounded in stacked non-Ethernet topologies and parse callbacks always run with the correct device context.

PUBLISHED Reserved 2026-03-09 | Published 2026-04-22 | Updated 2026-04-27 | Assigner Linux




HIGH: 7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Product status

Default status
unaffected

1d76efe1577b4323609b1bcbfafa8b731eda071a (git) before 6d3161fa3eee64d46b766fb0db33ec7f300ef52d
affected

1d76efe1577b4323609b1bcbfafa8b731eda071a (git) before 0a7468ed49a6b65d34abcc6eb60e15f7f6d34da0
affected

1d76efe1577b4323609b1bcbfafa8b731eda071a (git) before 20491d384d973a63fbdaf7a71e38d69b0659ea55
affected

1d76efe1577b4323609b1bcbfafa8b731eda071a (git) before 425000dbf17373a4ab8be9428f5dc055ef870a56
affected

Default status
affected

3.7
affected

Any version before 3.7
unaffected

6.12.80 (semver)
unaffected

6.18.21 (semver)
unaffected

6.19.11 (semver)
unaffected

7.0 (original_commit_for_fix)
unaffected

References

git.kernel.org/...c/6d3161fa3eee64d46b766fb0db33ec7f300ef52d

git.kernel.org/...c/0a7468ed49a6b65d34abcc6eb60e15f7f6d34da0

git.kernel.org/...c/20491d384d973a63fbdaf7a71e38d69b0659ea55

git.kernel.org/...c/425000dbf17373a4ab8be9428f5dc055ef870a56

cve.org (CVE-2026-31502)

nvd.nist.gov (CVE-2026-31502)

Download JSON