Description
In the Linux kernel, the following vulnerability has been resolved:

vlan: fix skb_under_panic and races when toggling HW VLAN offload

Toggling hardware VLAN TX offload (NETIF_F_HW_VLAN_CTAG_TX or
NETIF_F_HW_VLAN_STAG_TX) on a lower device invokes vlan_transfer_features(),
which dynamically changed vlandev->hard_header_len.

This causes two issues:
1. Lockless TX paths (e.g. packet_snd in af_packet.c, ip6_finish_output2)
read dev->hard_header_len without holding RTNL lock. Mutating
hard_header_len dynamically under RTNL creates a data race where upper
layers reserve insufficient headroom based on a stale hard_header_len,
resulting in skb_under_panic when vlan_dev_hard_header() is called.
2. In addition, vlan_transfer_features() updated hard_header_len without
updating header_ops, causing a mismatch between allocated headroom
and header creation.

Always setting dev->hard_header_len = real_dev->hard_header_len and
dev->needed_headroom = real_dev->needed_headroom + VLAN_HLEN unconditionally
ensures:
- dev->hard_header_len remains 100% static and immutable at real_dev->hard_header_len,
eliminating all dynamic runtime updates and data races on hard_header_len.
- Upper layers allocating skbs via LL_RESERVED_SPACE() will always reserve
sufficient headroom for software VLAN tag insertion (real_dev->hard_header_len +
real_dev->needed_headroom + VLAN_HLEN).
- vlandev inherits real_dev->needed_tailroom so underlying trailer/padding/ICV
requirements are honored.
- AF_PACKET SOCK_RAW network header offsets remain correctly aligned at
real_dev->hard_header_len.
- vlan_header_ops is used unconditionally.

Note to stable teams: Make sure to backport these commits:

e16e960d55a4 ("ipvlan: inherit needed_headroom and needed_tailroom from phy_dev")
cef51860becd ("macvlan: inherit needed_headroom and needed_tailroom from lowerdev")
Published: 2026-09-09
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via kernel crash
Action: Immediate Patch
AI Analysis

Impact

The vulnerability involves a data race in vlan_transfer_features that changes dev->hard_header_len without appropriate locking when toggling hardware VLAN offload. Lockless transmission paths then reserve insufficient headroom, causing skb_under_panic in functions such as packet_snd and ip6_finish_output2. The unchecked mismatch between allocated headroom and header creation can also lead to erroneous header insertion. The effect is a kernel panic, resulting in service interruption and denial of service.

Affected Systems

All releases of the Linux kernel that have not incorporated the backport commits e16e960d55a4 and cef51860becd. The problem emerges on any interface where NETIF_F_HW_VLAN_CTAG_TX or NETIF_F_HW_VLAN_STAG_TX can be toggled, regardless of the underlying hardware type.

Risk and Exploitability

No CVSS score is provided, but the patch mitigates a race condition that leads to a fatal exception; the consequence is a systemic crash rather than data leakage. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog at this time. Exploitation would likely require privileged access to modify offload settings on the target system, making local or highly privileged remote attack vectors the most plausible. While the exact likelihood of exploitation cannot be quantified, the crash potential warrants immediate attention.

Generated by OpenCVE AI on September 9, 2026 at 17:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the kernel patch that backports commits e16e960d55a4 and cef51860becd, ensuring hard_header_len remains immutable and needed_headroom/needed_tailroom are inherited correctly.
  • Disable or avoid dynamic toggling of NETIF_F_HW_VLAN_CTAG_TX and NETIF_F_HW_VLAN_STAG_TX on interfaces that are critical for stability.
  • Audit and lock interface configuration to prevent unintentional changes to VLAN offload settings, preferring a static deployment of hardware offload features.

Generated by OpenCVE AI on September 9, 2026 at 17:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 21 Sep 2026 13:30:00 +0000


Fri, 11 Sep 2026 10:15:00 +0000


Wed, 09 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: vlan: fix skb_under_panic and races when toggling HW VLAN offload Toggling hardware VLAN TX offload (NETIF_F_HW_VLAN_CTAG_TX or NETIF_F_HW_VLAN_STAG_TX) on a lower device invokes vlan_transfer_features(), which dynamically changed vlandev->hard_header_len. This causes two issues: 1. Lockless TX paths (e.g. packet_snd in af_packet.c, ip6_finish_output2) read dev->hard_header_len without holding RTNL lock. Mutating hard_header_len dynamically under RTNL creates a data race where upper layers reserve insufficient headroom based on a stale hard_header_len, resulting in skb_under_panic when vlan_dev_hard_header() is called. 2. In addition, vlan_transfer_features() updated hard_header_len without updating header_ops, causing a mismatch between allocated headroom and header creation. Always setting dev->hard_header_len = real_dev->hard_header_len and dev->needed_headroom = real_dev->needed_headroom + VLAN_HLEN unconditionally ensures: - dev->hard_header_len remains 100% static and immutable at real_dev->hard_header_len, eliminating all dynamic runtime updates and data races on hard_header_len. - Upper layers allocating skbs via LL_RESERVED_SPACE() will always reserve sufficient headroom for software VLAN tag insertion (real_dev->hard_header_len + real_dev->needed_headroom + VLAN_HLEN). - vlandev inherits real_dev->needed_tailroom so underlying trailer/padding/ICV requirements are honored. - AF_PACKET SOCK_RAW network header offsets remain correctly aligned at real_dev->hard_header_len. - vlan_header_ops is used unconditionally. Note to stable teams: Make sure to backport these commits: e16e960d55a4 ("ipvlan: inherit needed_headroom and needed_tailroom from phy_dev") cef51860becd ("macvlan: inherit needed_headroom and needed_tailroom from lowerdev")
Title vlan: fix skb_under_panic and races when toggling HW VLAN offload
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-21T13:14:17.708Z

Reserved: 2026-08-26T14:34:25.802Z

Link: CVE-2026-80925

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-09T17:17:47.763

Modified: 2026-09-21T14:17:21.290

Link: CVE-2026-80925

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T19:00:11Z

Weaknesses

No weakness.