Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
518 changes: 518 additions & 0 deletions pocs/linux/kernelctf/CVE-2026-43456_lts_cos_mitigation/docs/exploit.md

Large diffs are not rendered by default.

Original file line number Diff line number Diff line change
@@ -0,0 +1,31 @@
# Vulneribility

When a non-Ethernet device (e.g. GRE tunnel) is enslaved to a bond, bond_setup_by_slave() directly copies the slave's header_ops to the bond device:

bond_dev->header_ops = slave_dev->header_ops;

This causes a type confusion when dev_hard_header() is later called on the bond device. Functions like ipgre_header(), ip6gre_header(), all use
netdev_priv(dev) to access their device-specific private data. When called with the bond device, netdev_priv() returns the bond's private
data (struct bonding) instead of the expected type (e.g. struct ip_tunnel).

## Requirements to trigger the vulnerability
- Capabilities: `CAP_NET_ADMIN` capability is required.
- Kernel configuration: `CONFIG_BONDING`
- Are user namespaces needed?: Yes

## Commit which introduced the vulnerability
- [commit 1284cd3a2b740d0118458d2ea470a1e5bc19b187](https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=1284cd3a2b740d0118458d2ea470a1e5bc19b187)

## Commit which fixed the vulnerability
- [commit 950803f7254721c1c15858fbbfae3deaaeeecb11](https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=950803f7254721c1c15858fbbfae3deaaeeecb11)

## Affected kernel versions
- 2.6.24 - 6.12.77

## Affected component, subsystem
- net/bonding

## Cause
- Type-Confusion


Original file line number Diff line number Diff line change
@@ -0,0 +1,2 @@
exploit: exp.c
gcc exp.c -static -o exploit
Loading
Loading