Impact
The Linux kernel’s __vlan_insert_inner_tag() routine does not verify that a MAC header of the required length is present before it rewrites packet data. This oversight permits an attacker who can inject packets into an IFF_TUN interface to force the kernel to read beyond the valid data buffer, exposing uninitialized slab memory in outgoing frames. The flaw can leak kernel contents and may also corrupt packet payloads, potentially leading to crashes or anomalous behavior in downstream protocols.
Affected Systems
The vulnerability exists in all Linux kernel builds that include the default VLAN handling code prior to the fix. Any system that creates or manages IFF_TUN interfaces and transmits VLAN-tagged traffic is potentially impacted, regardless of distribution or hardware architecture.
Risk and Exploitability
A local attacker with CAP_NET_ADMIN can craft packets that trigger the out‑of‑bounds read. Because EPSS is not available and the CVSS score is not prescribed, exact exploit likelihood is uncertain, but the bug is significant. The issue is not listed in the CISA KEV catalog, indicating no known widespread exploitation yet. Updating to a kernel that enforces MAC header validation removes the vulnerability, though it requires a distribution update or kernel recompile and a reboot.
OpenCVE Enrichment