In the Linux kernel, the following vulnerability has been resolved: arp: do not assume devhardheader() does not change skb->head arpcreate() is the only devhardheader() caller making assumption about skb->head being unchanged. A recent commit broke this assumption. Initialize @arp pointer after devhard_header() call.