PT-2026-94426 · Linux · Linux Kernel
CVE-2026-90078
·
Published
2026-09-17
·
Updated
2026-09-24
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
Issues exist in the
tcf skbmod act() function regarding length calculations and header handling. The function incorrectly assumes the transport header is set when calling skb network header len(), which may not be true during TC ingress. Additionally, calling skb mac header len() unconditionally can trigger warnings on L3 devices, such as TUN, where the MAC header is unset, leading to underflowed length values. Furthermore, on TC ingress, adding the MAC header length to the IP header length causes skb ensure writable() to request more bytes than the actual IP packet length, resulting in the dropping of valid short packets, such as 28-byte UDP/IPv4 packets.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel