PT-2026-108763 · Linux · Linux

CVE-2026-98377

·

Publicado

2026-10-09

·

Atualizado

2026-10-09

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
vlan: require the MAC header to be present in vlan insert inner tag()
vlan insert inner tag() only guarantees head room via skb cow head(), never that mac len bytes of MAC header are present. Its ETH HLEN wrappers - vlan insert tag() under skb vlan push(), and vlan insert tag() under validate xmit vlan() on the generic transmit path - therefore rewrite the first 16 bytes at skb->data: a 12-byte memmove plus two 2-byte stores at +12 and +14. No caller supplies the bound, while the pop helpers use skb ensure writable()/pskb may pull().
An IFF TUN device has hard header len == 0, so packet snd() accepts a one-byte AF PACKET/SOCK RAW frame. The first vlan push only sets a hwaccel tag; the next - clsact "action vlan push" or bpf skb vlan push() - enters the helper with skb->len still 1. The head comes from skbuff small head without GFP ZERO, so each push drags bytes from beyond skb->tail into the frame. After three the one-byte send leaves as 13 bytes carrying 11 bytes of uninitialised slab:
0000: 5a b3 62 12 80 88 ff ff 00 b3 62 12 81 `------------------------------' only 0x5a was sent; the rest is slab, here the top 56 bits of a linear-map address
Require the MAC header the helper rewrites to be present, so such a frame is dropped rather than transmitted.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2026-98377

Produtos afetados

Linux