Linux Kernel Macsec Replay Protection Vulnerability in XPN Lower-PN Wrap

Vulnerability

A vulnerability in the Linux kernel's MACsec implementation allows for indefinite replay of frames under certain conditions. This issue arises when the packet number (PN) is at its maximum value, causing an overflow that disrupts proper sequence number handling. As a result, an attacker can capture and replay frames, exploiting the MACsec decryption process to reconstruct the same initialization vector (IV) and potentially interfere with secure communications.

Impact

The vulnerability allows an attacker to replay captured MACsec frames indefinitely, disrupting secure communications by causing the receiver to process the same frame multiple times as if it were new.

Reproduction

To reproduce this vulnerability, send a MACsec frame with a packet number (PN) of 0xFFFFFFFF. The receiver will not properly advance its sequence number, allowing the frame to be replayed indefinitely.

Remediation

Users can upgrade to the latest stable version of the Linux kernel, where this vulnerability has been addressed.

Added: Jul 19, 2026, 7:58 PM
Updated: Jul 19, 2026, 7:58 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
0.6
exploitability
5.3
remediation
7.7
relevance
9.7
threat
4.8
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.