CVE-2026-98377: vlan: require the MAC header to be present in __vlan_insert_inner_tag()
In the Linux kernel, the following vulnerability has been resolved:
vlan: require the MAC header to be present in vlaninsertinnertag()
vlaninsertinnertag() only guarantees head room via skbcowhead(), never that maclen bytes of MAC header are present. Its ETHHLEN wrappers - vlaninserttag() under skbvlanpush(), and vlaninserttag() under validatexmitvlan() on the generic transmit path - therefore rewrite the first 16 bytes at skb->data: a 12-byte memmove plus two 2-byte stores at +12 and +14. No caller supplies the bound, while the pop helpers use skbensurewritable()/pskbmaypull().
An IFFTUN device has hardheaderlen == 0, so packetsnd() accepts a one-byte AFPACKET/SOCKRAW frame. The first vlan push only sets a hwaccel tag; the next - clsact "action vlan push" or bpfskbvlanpush() - enters the helper with skb->len still 1. The head comes from skbuffsmallhead without GFPZERO, so each push drags bytes from beyond skb->tail into the frame. After three the one-byte send leaves as 13 bytes carrying 11 bytes of uninitialised slab:
0000: 5a b3 62 12 80 88 ff ff 00 b3 62 12 81 ------------------------------' only 0x5a was sent; the rest is slab, here the top 56 bits of a linear-map address
Require the MAC header the helper rewrites to be present, so such a frame is dropped rather than transmitted.
Affected Software
Event History
Frequently Asked Questions
What conditions are needed to trigger the information leak?
An attacker needs to send a one-byte AF_PACKET/SOCK_RAW frame through an IFF_TUN device, whose hard_header_len is zero, and cause additional VLAN tag pushes. The described paths for the additional pushes are a clsact "action vlan push" rule or bpf_skb_vlan_push().
Is a single VLAN push sufficient to expose uninitialized memory?
No. The first VLAN push only sets a hardware-accelerated VLAN tag while the packet length remains one byte. Subsequent pushes enter the vulnerable helper, and after three pushes the one-byte transmission is described as leaving as a 13-byte frame containing 11 bytes of uninitialized slab data.
Which kernel networking configurations are most relevant for exposure?
Exposure requires an IFF_TUN device and a mechanism that performs repeated VLAN pushes, such as clsact VLAN push actions or BPF code using bpf_skb_vlan_push(). The provided data does not establish that ordinary Ethernet-only configurations without these conditions are affected.
What is the remediation indicated by the provided data?
Apply a Linux kernel update containing the referenced stable commits. The fix requires the MAC header to be present in __vlan_insert_inner_tag(), rather than only ensuring headroom.