CVE-2026-98377: vlan: require the MAC header to be present in __vlan_insert_inner_tag()

Published Oct 9, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

vlan: require the MAC header to be present in vlaninsertinnertag()

vlaninsertinnertag() only guarantees head room via skbcowhead(), never that maclen bytes of MAC header are present. Its ETHHLEN wrappers - vlaninserttag() under skbvlanpush(), and vlaninserttag() under validatexmitvlan() on the generic transmit path - therefore rewrite the first 16 bytes at skb->data: a 12-byte memmove plus two 2-byte stores at +12 and +14. No caller supplies the bound, while the pop helpers use skbensurewritable()/pskbmaypull().

An IFFTUN device has hardheaderlen == 0, so packetsnd() accepts a one-byte AFPACKET/SOCKRAW frame. The first vlan push only sets a hwaccel tag; the next - clsact "action vlan push" or bpfskbvlanpush() - enters the helper with skb->len still 1. The head comes from skbuffsmallhead without GFPZERO, so each push drags bytes from beyond skb->tail into the frame. After three the one-byte send leaves as 13 bytes carrying 11 bytes of uninitialised slab:

0000: 5a b3 62 12 80 88 ff ff 00 b3 62 12 81 ------------------------------' only 0x5a was sent; the rest is slab, here the top 56 bits of a linear-map address

Require the MAC header the helper rewrites to be present, so such a frame is dropped rather than transmitted.

Affected Software

1 affected component
Linux Linux kernel

Event History

Oct 9, 2026
CVE Published
via MITRE·07:34 AM
Data Sourced
via MITRE·07:34 AM
Description
Data Sourced
via NVD·08:16 AM
Description

Frequently Asked Questions

1

What conditions are needed to trigger the information leak?

An attacker needs to send a one-byte AF_PACKET/SOCK_RAW frame through an IFF_TUN device, whose hard_header_len is zero, and cause additional VLAN tag pushes. The described paths for the additional pushes are a clsact "action vlan push" rule or bpf_skb_vlan_push().

2

Is a single VLAN push sufficient to expose uninitialized memory?

No. The first VLAN push only sets a hardware-accelerated VLAN tag while the packet length remains one byte. Subsequent pushes enter the vulnerable helper, and after three pushes the one-byte transmission is described as leaving as a 13-byte frame containing 11 bytes of uninitialized slab data.

3

Which kernel networking configurations are most relevant for exposure?

Exposure requires an IFF_TUN device and a mechanism that performs repeated VLAN pushes, such as clsact VLAN push actions or BPF code using bpf_skb_vlan_push(). The provided data does not establish that ordinary Ethernet-only configurations without these conditions are affected.

4

What is the remediation indicated by the provided data?

Apply a Linux kernel update containing the referenced stable commits. The fix requires the MAC header to be present in __vlan_insert_inner_tag(), rather than only ensuring headroom.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203