PT-2026-108763 · Linux · Linux

CVE-2026-98377

·

Published

2026-10-09

·

Updated

2026-10-09

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
vlan: require the MAC header to be present in vlan insert inner tag()
vlan insert inner tag() only guarantees head room via skb cow head(), never that mac len bytes of MAC header are present. Its ETH HLEN wrappers - vlan insert tag() under skb vlan push(), and vlan insert tag() under validate xmit vlan() on the generic transmit path - therefore rewrite the first 16 bytes at skb->data: a 12-byte memmove plus two 2-byte stores at +12 and +14. No caller supplies the bound, while the pop helpers use skb ensure writable()/pskb may pull().
An IFF TUN device has hard header len == 0, so packet snd() accepts a one-byte AF PACKET/SOCK RAW frame. The first vlan push only sets a hwaccel tag; the next - clsact "action vlan push" or bpf skb vlan push() - enters the helper with skb->len still 1. The head comes from skbuff small head without GFP ZERO, so each push drags bytes from beyond skb->tail into the frame. After three the one-byte send leaves as 13 bytes carrying 11 bytes of uninitialised slab:
0000: 5a b3 62 12 80 88 ff ff 00 b3 62 12 81 `------------------------------' only 0x5a was sent; the rest is slab, here the top 56 bits of a linear-map address
Require the MAC header the helper rewrites to be present, so such a frame is dropped rather than transmitted.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-98377

Affected Products

Linux