Description
In the Linux kernel, the following vulnerability has been resolved:

net/sched: act_skbmod: fix length calculations and avoid invalid header warnings

syzbot reported a warning in skb_network_header_len() triggered
by tcf_skbmod_act():

!skb_transport_header_was_set(skb)
WARNING: CPU: 0 PID: 14949 at include/linux/skbuff.h:3243 skb_network_header_len include/linux/skbuff.h:3243 [inline]
WARNING: CPU: 0 PID: 14949 at net/sched/act_skbmod.c:55 tcf_skbmod_act+0xfe8/0x1810 net/sched/act_skbmod.c:55

There are a few issues in tcf_skbmod_act():

1. Calling skb_network_header_len() assumes skb->transport_header is set,
which is not guaranteed when tcf_skbmod_act() runs at TC ingress.
2. Unconditionally calling skb_mac_header_len() at the beginning of
tcf_skbmod_act() triggers a warning on L3 devices (e.g. TUN) where the
MAC header is unset, evaluating to an underflowed garbage length.
3. On TC ingress, skb->data points to the network header. Adding the MAC
header length to the IP header length causes skb_ensure_writable() to
request more bytes than the actual IP packet length, dropping valid
short packets (e.g. 28-byte UDP/IPv4 packets).

Fix these by:
- Using skb_network_offset(skb) + sizeof(struct iphdr/ipv6hdr) for
SKBMOD_F_ECN so that the required length is correctly calculated on
both ingress (offset == 0) and egress (offset == mac_len).
- Setting max_edit_len to ETH_HLEN for Ethernet header modifications
after validating ARPHRD_ETHER.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service by dropping valid short packets
Action: Apply patch
AI Analysis

Impact

A flaw in the Linux kernel’s traffic-control skbmod action miscalculates buffer lengths when processing packets on TC ingress. The incorrect calculations trigger warnings, cause skb_ensure_writable to request more space than the packet holds, and result in legitimate short packets (for example, 28‑byte UDP/IPv4 packets) being dropped. The vulnerability therefore enables an attacker to induce packet loss and disrupt network communication, but it does not provide a path to arbitrary code execution or privilege escalation.

Affected Systems

The defect resides in the Linux kernel’s traffic‑control subsystem, affecting any Linux system whose kernel implements the act_skbmod filter for TC ingress operations. Specific kernel releases are not enumerated, so all affected kernels prior to the fix should be considered vulnerable.

Risk and Exploitability

The CVSS score is not provided, and the EPSS score is less than 1 %, indicating a very low probability of actual exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Exploitation would likely require an attacker to be able to influence packets processed by the TC ingress hook—either by sending crafted packets to a device such as a TUN interface or by running code on the host that applies the vulnerable tcf_skbmod action. While the impact is limited to denial of service through packet drops, low EPSS and lack of broader exploitation vectors keep the overall risk moderate on a system‑wide scale.

Generated by OpenCVE AI on September 20, 2026 at 04:27 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a Linux kernel version that includes the act_skbmod length‑calculation fix referenced in the supplied commit logs.
  • If a kernel upgrade is not immediately possible, remove or disable any TC ingress rules that use the tcf_skbmod action on L3 devices such as TUN interfaces to prevent packet loss.
  • Ensure that any remaining MAC header modifications apply the ARPHRD_ETHER validation before adding ETH_HLEN to avoid erroneous length calculations.

Generated by OpenCVE AI on September 20, 2026 at 04:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 20 Sep 2026 04:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
CWE-190
CWE-787

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: net/sched: act_skbmod: fix length calculations and avoid invalid header warnings syzbot reported a warning in skb_network_header_len() triggered by tcf_skbmod_act(): !skb_transport_header_was_set(skb) WARNING: CPU: 0 PID: 14949 at include/linux/skbuff.h:3243 skb_network_header_len include/linux/skbuff.h:3243 [inline] WARNING: CPU: 0 PID: 14949 at net/sched/act_skbmod.c:55 tcf_skbmod_act+0xfe8/0x1810 net/sched/act_skbmod.c:55 There are a few issues in tcf_skbmod_act(): 1. Calling skb_network_header_len() assumes skb->transport_header is set, which is not guaranteed when tcf_skbmod_act() runs at TC ingress. 2. Unconditionally calling skb_mac_header_len() at the beginning of tcf_skbmod_act() triggers a warning on L3 devices (e.g. TUN) where the MAC header is unset, evaluating to an underflowed garbage length. 3. On TC ingress, skb->data points to the network header. Adding the MAC header length to the IP header length causes skb_ensure_writable() to request more bytes than the actual IP packet length, dropping valid short packets (e.g. 28-byte UDP/IPv4 packets). Fix these by: - Using skb_network_offset(skb) + sizeof(struct iphdr/ipv6hdr) for SKBMOD_F_ECN so that the required length is correctly calculated on both ingress (offset == 0) and egress (offset == mac_len). - Setting max_edit_len to ETH_HLEN for Ethernet header modifications after validating ARPHRD_ETHER.
Title net/sched: act_skbmod: fix length calculations and avoid invalid header warnings
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:05:56.878Z

Reserved: 2026-09-11T19:38:34.785Z

Link: CVE-2026-90078

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:16:57.057

Modified: 2026-09-17T17:16:57.057

Link: CVE-2026-90078

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T04:30:18Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-190

    Integer Overflow or Wraparound

  • CWE-787

    Out-of-bounds Write