-

CVE-2026-98377

vlan: require the MAC header to be present in __vlan_insert_inner_tag()

In the Linux kernel, the following vulnerability has been resolved:

vlan: require the MAC header to be present in __vlan_insert_inner_tag()

__vlan_insert_inner_tag() only guarantees head room via skb_cow_head(),
never that mac_len bytes of MAC header are present.  Its ETH_HLEN
wrappers - __vlan_insert_tag() under skb_vlan_push(), and
vlan_insert_tag() under validate_xmit_vlan() on the generic transmit
path - therefore rewrite the first 16 bytes at skb->data: a 12-byte
memmove plus two 2-byte stores at +12 and +14.  No caller supplies the
bound, while the pop helpers use skb_ensure_writable()/pskb_may_pull().

An IFF_TUN device has hard_header_len == 0, so packet_snd() accepts a
one-byte AF_PACKET/SOCK_RAW frame.  The first vlan push only sets a
hwaccel tag; the next - clsact "action vlan push" or
bpf_skb_vlan_push() - enters the helper with skb->len still 1.  The
head comes from skbuff_small_head without __GFP_ZERO, so each push
drags bytes from beyond skb->tail into the frame.  After three the
one-byte send leaves as 13 bytes carrying 11 bytes of uninitialised
slab:

  0000: 5a b3 62 12 80 88 ff ff 00 b3 62 12 81
           `------------------------------'
  only 0x5a was sent; the rest is slab, here the top 56 bits of a
  linear-map address

Require the MAC header the helper rewrites to be present, so such a
frame is dropped rather than transmitted.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < 40a5cc4b7251c74f3341332a226d02200e96bccf
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < f42562dd027dc4ed103fae17b2206e73ea1963c4
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < 59af43ccece4d2d8b62e9e3ccc96b6e2e793bcdc
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < ab888242fce4f16f6c4d4c6ec53939ad36aa3b3a
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 2.6.12
Status affected
Version 0
Version < 2.6.12
Status unaffected
Version <= 6.12.*
Version 6.12.112
Status unaffected
Version <= 6.18.*
Version 6.18.55
Status unaffected
Version <= 7.2.*
Version 7.2.9
Status unaffected
Version <= *
Version 7.3-rc5
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.16% 0.042
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/40a5cc4b7251c74f3341332a226d02200e96bccf
https://git.kernel.org/stable/c/f42562dd027dc4ed103fae17b2206e73ea1963c4
https://git.kernel.org/stable/c/59af43ccece4d2d8b62e9e3ccc96b6e2e793bcdc
https://git.kernel.org/stable/c/ab888242fce4f16f6c4d4c6ec53939ad36aa3b3a