Куда я попал?
SECURITM это SGRC система, ? автоматизирующая процессы в службах информационной безопасности. SECURITM помогает построить и управлять ИСПДн, КИИ, ГИС, СМИБ/СУИБ, банковскими системами защиты.
А еще SECURITM это место для обмена опытом и наработками для служб безопасности.

CVE-2025-68340

PUBLISHED 05.08.2026

CNA: Linux

team: Move team device type change at the end of team_port_add

Обновлено: 05.08.2026
In the Linux kernel, the following vulnerability has been resolved: team: Move team device type change at the end of team_port_add Attempting to add a port device that is already up will expectedly fail, but not before modifying the team device header_ops. In the case of the syzbot reproducer the gre0 device is already in state UP when it attempts to add it as a port device of team0, this fails but before that header_ops->create of team0 is changed from eth_header to ipgre_header in the call to team_dev_type_check_change. Later when we end up in ipgre_header() struct ip_tunnel* points to nonsense as the private data of the device still holds a struct team. Example sequence of iproute2 commands to reproduce the hang/BUG(): ip link add dev team0 type team ip link add dev gre0 type gre ip link set dev gre0 up ip link set dev gre0 master team0 ip link set dev team0 up ping -I team0 1.1.1.1 Move team_dev_type_check_change down where all other checks have passed as it changes the dev type with no way to restore it in case one of the checks that follow it fail. Also make sure to preserve the origial mtu assignment: - If port_dev is not the same type as dev, dev takes mtu from port_dev - If port_dev is the same type as dev, port_dev takes mtu from dev This is done by adding a conditional before the call to dev_set_mtu to prevent it from assigning port_dev->mtu = dev->mtu and instead letting team_dev_type_check_change assign dev->mtu = port_dev->mtu. The conditional is needed because the patch moves the call to team_dev_type_check_change past dev_set_mtu. Testing: - team device driver in-tree selftests - Add/remove various devices as slaves of team device - syzbot

БДУ ФСТЭК

Идентификатор Описание
BDU:2026-09418 Уязвимость функции team_port_add() в модуле drivers/net/team/team_core.c драйвера сетевых устройств ядра операционной системы Linux, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

CVSS

Оценка Severity Версия Базовый вектор
7.8 HIGH 3.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

Вероятность Severity Процентиль ? Дата расчёта
0.02% LOW 6.99 23.05.2026

Доп. Информация

Product Status

Linux
Product: Linux
Vendor: Linux
Default status: unaffected
Версии:
Затронутые версии Статус
Наблюдалось в версиях от 1d76efe1577b4323609b1bcbfafa8b731eda071a до f82d1fb65549de241fe312fcb2bcb8e0ad7b424d affected
Наблюдалось в версиях от 1d76efe1577b4323609b1bcbfafa8b731eda071a до c8b15b0d2eec3b5c7f585e5a53dfc8d36c818283 affected
Наблюдалось в версиях от 1d76efe1577b4323609b1bcbfafa8b731eda071a до a74ab1b532ecc5f9106621a8f75b4c3d04466b35 affected
Наблюдалось в версиях от 1d76efe1577b4323609b1bcbfafa8b731eda071a до e26235840fd961e4ebe5568f11a2a078cf726663 affected
Наблюдалось в версиях от 1d76efe1577b4323609b1bcbfafa8b731eda071a до 4040b5e8963982a00aa821300cb746efc9f2947e affected
Наблюдалось в версиях от 1d76efe1577b4323609b1bcbfafa8b731eda071a до e3eed4f038214494af62c7d2d64749e5108ce6ca affected
Наблюдалось в версиях от 1d76efe1577b4323609b1bcbfafa8b731eda071a до 0ae9cfc454ea5ead5f3ddbdfe2e70270d8e2c8ef affected
Linux
Product: Linux
Vendor: Linux
Default status: affected
Версии:
Затронутые версии Статус
Наблюдалось в версии 3.7 affected
Наблюдалось в версиях от 0 до 3.7 unaffected
Наблюдалось до версии 5.10.* unaffected
Наблюдалось до версии 5.15.* unaffected
Наблюдалось до версии 6.1.* unaffected
Наблюдалось до версии 6.6.* unaffected
Наблюдалось до версии 6.12.* unaffected
Наблюдалось до версии 6.17.* unaffected
Наблюдалось до версии * unaffected
 

Ссылки

Мы используем cookie-файлы, чтобы получить статистику, которая помогает нам улучшить сервис для вас с целью персонализации сервисов и предложений. Вы может прочитать подробнее о cookie-файлах или изменить настройки браузера. Продолжая пользоваться сайтом, вы даёте согласие на использование ваших cookie-файлов и соглашаетесь с Политикой обработки персональных данных.