CVE-2026-53069 Details
Description
In the Linux kernel, the following vulnerability has been resolved: net, bpf: fix null-ptr-deref in xdp_master_redirect() for down master syzkaller reported a kernel panic in bond_rr_gen_slave_id() reached via xdp_master_redirect(). Full decoded trace: https://syzkaller.appspot.com/bug?extid=80e046b8da2820b6ba73 bond_rr_gen_slave_id() dereferences bond->rr_tx_counter, a per-CPU counter that bonding only allocates in bond_open() when the mode is round-robin. If the bond device was never brought up, rr_tx_counter stays NULL. The XDP redirect path can still reach that code on a bond that was never opened: bpf_master_redirect_enabled_key is a global static key, so as soon as any bond device has native XDP attached, the XDP_TX -> xdp_master_redirect() interception is enabled for every slave system-wide. The path xdp_master_redirect() -> bond_xdp_get_xmit_slave() -> bond_xdp_xmit_roundrobin_slave_get() -> bond_rr_gen_slave_id() then runs against a bond that has no rr_tx_counter and crashes. Fix this in the generic xdp_master_redirect() by refusing to call into the master's ->ndo_xdp_get_xmit_slave() when the master device is not up. IFF_UP is only set after ->ndo_open() has successfully returned, so this reliably excludes masters whose XDP state has not been fully initialized. Drop the frame with XDP_ABORTED so the exception is visible via trace_xdp_exception() rather than silently falling through. This is not specific to bonding: any current or future master that defers XDP state allocation to ->ndo_open() is protected.
A null pointer dereference vulnerability has been identified in the Linux kernel's handling of XDP (eXpress Data Path) redirection for bond devices using round-robin transmission. This issue arises because the bonding mechanism only allocates a necessary per-CPU counter when the bond is active. If a bond device is not brought up, this counter remains null. Despite this, the XDP redirect can still invoke a path that dereferences the null counter, leading to a kernel panic. The vulnerability is present in the stable versions of the Linux kernel.
The vulnerability has been fixed in the Linux kernel. Users should upgrade to the latest version.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/183128da0406b1c10e6f60b7b9fe70788b9c8c1d | kernel.org | Patch |
| https://git.kernel.org/stable/c/1921f91298d1388a0bb9db8f83800c998b649cb3 | kernel.org | Patch |
| https://git.kernel.org/stable/c/3128b294b426533c8d9162187446d93a8a160359 | kernel.org | Patch |
| https://git.kernel.org/stable/c/7bad93e99737e4a5c0c14ac50c05152cf4e28022 | kernel.org | Patch |
| https://git.kernel.org/stable/c/866d3d9b87751b1944168fd82615505e0c0fd6cf | kernel.org | Patch |
| https://git.kernel.org/stable/c/acbf45bd584d924b320bee2a7fe2a26f64904d95 | kernel.org | Patch |
| https://git.kernel.org/stable/c/ea690b3b6e58ae00979af8195b4cc24df466b65e | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-476 | NULL Pointer Dereference | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 5.15, < 5.15.209 >= 5.16, < 6.1.175 >= 6.2, < 6.6.141 >= 6.7, < 6.12.91 >= 6.13, < 6.18.33 >= 6.19, < 7.0.10 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 21, 2026 | Initial Analysis | [email protected] |
| Jun 28, 2026 | CVE Modified | kernel.org |
| Jun 24, 2026 | New CVE Received | kernel.org |