PT-2026-108763 · Linux · Linux
CVE-2026-98377
·
Published
2026-10-09
·
Updated
2026-10-09
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
vlan: require the MAC header to be present in vlan insert inner tag()
vlan insert inner tag() only guarantees head room via skb cow head(),
never that mac len bytes of MAC header are present. Its ETH HLEN
wrappers - vlan insert tag() under skb vlan push(), and
vlan insert tag() under validate xmit vlan() on the generic transmit
path - therefore rewrite the first 16 bytes at skb->data: a 12-byte
memmove plus two 2-byte stores at +12 and +14. No caller supplies the
bound, while the pop helpers use skb ensure writable()/pskb may pull().
An IFF TUN device has hard header len == 0, so packet snd() accepts a
one-byte AF PACKET/SOCK RAW frame. The first vlan push only sets a
hwaccel tag; the next - clsact "action vlan push" or
bpf skb vlan push() - enters the helper with skb->len still 1. The
head comes from skbuff small head without GFP ZERO, so each push
drags bytes from beyond skb->tail into the frame. After three the
one-byte send leaves as 13 bytes carrying 11 bytes of uninitialised
slab:
0000: 5a b3 62 12 80 88 ff ff 00 b3 62 12 81
`------------------------------'
only 0x5a was sent; the rest is slab, here the top 56 bits of a
linear-map address
Require the MAC header the helper rewrites to be present, so such a
frame is dropped rather than transmitted.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux