PT-2026-108763 · Linux · Linux
CVE-2026-98377
·
Publicado
2026-10-09
·
Atualizado
2026-10-09
Nenhuma
Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
vlan: require the MAC header to be present in vlan insert inner tag()
vlan insert inner tag() only guarantees head room via skb cow head(),
never that mac len bytes of MAC header are present. Its ETH HLEN
wrappers - vlan insert tag() under skb vlan push(), and
vlan insert tag() under validate xmit vlan() on the generic transmit
path - therefore rewrite the first 16 bytes at skb->data: a 12-byte
memmove plus two 2-byte stores at +12 and +14. No caller supplies the
bound, while the pop helpers use skb ensure writable()/pskb may pull().
An IFF TUN device has hard header len == 0, so packet snd() accepts a
one-byte AF PACKET/SOCK RAW frame. The first vlan push only sets a
hwaccel tag; the next - clsact "action vlan push" or
bpf skb vlan push() - enters the helper with skb->len still 1. The
head comes from skbuff small head without GFP ZERO, so each push
drags bytes from beyond skb->tail into the frame. After three the
one-byte send leaves as 13 bytes carrying 11 bytes of uninitialised
slab:
0000: 5a b3 62 12 80 88 ff ff 00 b3 62 12 81
`------------------------------'
only 0x5a was sent; the rest is slab, here the top 56 bits of a
linear-map address
Require the MAC header the helper rewrites to be present, so such a
frame is dropped rather than transmitted.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Linux