Description
In the Linux kernel, the following vulnerability has been resolved:

vlan: require the MAC header to be present in __vlan_insert_inner_tag()

__vlan_insert_inner_tag() only guarantees head room via skb_cow_head(),
never that mac_len bytes of MAC header are present. Its ETH_HLEN
wrappers - __vlan_insert_tag() under skb_vlan_push(), and
vlan_insert_tag() under validate_xmit_vlan() on the generic transmit
path - therefore rewrite the first 16 bytes at skb->data: a 12-byte
memmove plus two 2-byte stores at +12 and +14. No caller supplies the
bound, while the pop helpers use skb_ensure_writable()/pskb_may_pull().

An IFF_TUN device has hard_header_len == 0, so packet_snd() accepts a
one-byte AF_PACKET/SOCK_RAW frame. The first vlan push only sets a
hwaccel tag; the next - clsact "action vlan push" or
bpf_skb_vlan_push() - enters the helper with skb->len still 1. The
head comes from skbuff_small_head without __GFP_ZERO, so each push
drags bytes from beyond skb->tail into the frame. After three the
one-byte send leaves as 13 bytes carrying 11 bytes of uninitialised
slab:

0000: 5a b3 62 12 80 88 ff ff 00 b3 62 12 81
`------------------------------'
only 0x5a was sent; the rest is slab, here the top 56 bits of a
linear-map address

Require the MAC header the helper rewrites to be present, so such a
frame is dropped rather than transmitted.
Published: 2026-10-09
Score: n/a
EPSS: n/a
KEV: No
Impact: Potential information disclosure via uninitialized memory in VLAN stack
Action: Apply patch
AI Analysis

Impact

The Linux kernel’s __vlan_insert_inner_tag() routine does not verify that a MAC header of the required length is present before it rewrites packet data. This oversight permits an attacker who can inject packets into an IFF_TUN interface to force the kernel to read beyond the valid data buffer, exposing uninitialized slab memory in outgoing frames. The flaw can leak kernel contents and may also corrupt packet payloads, potentially leading to crashes or anomalous behavior in downstream protocols.

Affected Systems

The vulnerability exists in all Linux kernel builds that include the default VLAN handling code prior to the fix. Any system that creates or manages IFF_TUN interfaces and transmits VLAN-tagged traffic is potentially impacted, regardless of distribution or hardware architecture.

Risk and Exploitability

A local attacker with CAP_NET_ADMIN can craft packets that trigger the out‑of‑bounds read. Because EPSS is not available and the CVSS score is not prescribed, exact exploit likelihood is uncertain, but the bug is significant. The issue is not listed in the CISA KEV catalog, indicating no known widespread exploitation yet. Updating to a kernel that enforces MAC header validation removes the vulnerability, though it requires a distribution update or kernel recompile and a reboot.

Generated by OpenCVE AI on October 9, 2026 at 09:30 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install the kernel update that includes the patch to enforce MAC header presence before VLAN tag insertion
  • Reboot the system so the updated kernel version is in use
  • If a patch is not immediately available, restrict or disable IFF_TUN interfaces that create VLAN-tagged traffic to prevent the kernel from processing packets that could trigger the flaw

Generated by OpenCVE AI on October 9, 2026 at 09:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 10:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-229
CWE-788

Fri, 09 Oct 2026 08:00:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: vlan: require the MAC header to be present in __vlan_insert_inner_tag() __vlan_insert_inner_tag() only guarantees head room via skb_cow_head(), never that mac_len bytes of MAC header are present. Its ETH_HLEN wrappers - __vlan_insert_tag() under skb_vlan_push(), and vlan_insert_tag() under validate_xmit_vlan() on the generic transmit path - therefore rewrite the first 16 bytes at skb->data: a 12-byte memmove plus two 2-byte stores at +12 and +14. No caller supplies the bound, while the pop helpers use skb_ensure_writable()/pskb_may_pull(). An IFF_TUN device has hard_header_len == 0, so packet_snd() accepts a one-byte AF_PACKET/SOCK_RAW frame. The first vlan push only sets a hwaccel tag; the next - clsact "action vlan push" or bpf_skb_vlan_push() - enters the helper with skb->len still 1. The head comes from skbuff_small_head without __GFP_ZERO, so each push drags bytes from beyond skb->tail into the frame. After three the one-byte send leaves as 13 bytes carrying 11 bytes of uninitialised slab: 0000: 5a b3 62 12 80 88 ff ff 00 b3 62 12 81 `------------------------------' only 0x5a was sent; the rest is slab, here the top 56 bits of a linear-map address Require the MAC header the helper rewrites to be present, so such a frame is dropped rather than transmitted.
Title vlan: require the MAC header to be present in __vlan_insert_inner_tag()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-10-09T07:34:17.832Z

Reserved: 2026-09-25T10:25:14.345Z

Link: CVE-2026-98377

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-09T08:16:56.010

Modified: 2026-10-09T08:16:56.010

Link: CVE-2026-98377

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T09:45:04Z

Weaknesses
  • CWE-229

    Improper Handling of Values

  • CWE-788

    Access of Memory Location After End of Buffer