---
id: CVE-2026-98377
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  vlan: require the MAC header to be present in __vlan_insert_inner_tag()

  __vlan_insert_inner_tag() only guarantees head room via skb_cow_head(),
  never that mac_len byte…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  vlan: require the MAC header to be present in __vlan_insert_inner_tag()

  __vlan_insert_inner_tag() only guarantees head room via skb_cow_head(),
  never that mac_len byte…
severity: none
published: '2026-10-09'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T08:16:56.010'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-98377'
references:
  - url: 'https://git.kernel.org/stable/c/40a5cc4b7251c74f3341332a226d02200e96bccf'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/59af43ccece4d2d8b62e9e3ccc96b6e2e793bcdc'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/ab888242fce4f16f6c4d4c6ec53939ad36aa3b3a'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/f42562dd027dc4ed103fae17b2206e73ea1963c4'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
ingestedAt: '2026-10-09T08:29:41.350Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

vlan: require the MAC header to be present in __vlan_insert_inner_tag()

__vlan_insert_inner_tag() only guarantees head room via skb_cow_head(),
never that mac_len bytes of MAC header are present.  Its ETH_HLEN
wrappers - __vlan_insert_tag() under skb_vlan_push(), and
vlan_insert_tag() under validate_xmit_vlan() on the generic transmit
path - therefore rewrite the first 16 bytes at skb->data: a 12-byte
memmove plus two 2-byte stores at +12 and +14.  No caller supplies the
bound, while the pop helpers use skb_ensure_writable()/pskb_may_pull().

An IFF_TUN device has hard_header_len == 0, so packet_snd() accepts a
one-byte AF_PACKET/SOCK_RAW frame.  The first vlan push only sets a
hwaccel tag; the next - clsact "action vlan push" or
bpf_skb_vlan_push() - enters the helper with skb->len still 1.  The
head comes from skbuff_small_head without __GFP_ZERO, so each push
drags bytes from beyond skb->tail into the frame.  After three the
one-byte send leaves as 13 bytes carrying 11 bytes of uninitialised
slab:

  0000: 5a b3 62 12 80 88 ff ff 00 b3 62 12 81
           `------------------------------'
  only 0x5a was sent; the rest is slab, here the top 56 bits of a
  linear-map address

Require the MAC header the helper rewrites to be present, so such a
frame is dropped rather than transmitted.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
