{
  "affected": [
    {
      "ranges": [
        {
          "events": [
            {
              "introduced": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2"
            },
            {
              "fixed": "40a5cc4b7251c74f3341332a226d02200e96bccf"
            },
            {
              "fixed": "f42562dd027dc4ed103fae17b2206e73ea1963c4"
            },
            {
              "fixed": "59af43ccece4d2d8b62e9e3ccc96b6e2e793bcdc"
            },
            {
              "fixed": "ab888242fce4f16f6c4d4c6ec53939ad36aa3b3a"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        }
      ]
    },
    {
      "package": {
        "ecosystem": "Linux",
        "name": "Kernel"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "2.6.12"
            },
            {
              "fixed": "6.12.112"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.13.0"
            },
            {
              "fixed": "6.18.55"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.19.0"
            },
            {
              "fixed": "7.2.9"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "database_specific": {
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98377.json"
  },
  "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nvlan: require the MAC header to be present in __vlan_insert_inner_tag()\n\n__vlan_insert_inner_tag() only guarantees head room via skb_cow_head(),\nnever that mac_len bytes of MAC header are present.  Its ETH_HLEN\nwrappers - __vlan_insert_tag() under skb_vlan_push(), and\nvlan_insert_tag() under validate_xmit_vlan() on the generic transmit\npath - therefore rewrite the first 16 bytes at skb-\u003edata: a 12-byte\nmemmove plus two 2-byte stores at +12 and +14.  No caller supplies the\nbound, while the pop helpers use skb_ensure_writable()/pskb_may_pull().\n\nAn IFF_TUN device has hard_header_len == 0, so packet_snd() accepts a\none-byte AF_PACKET/SOCK_RAW frame.  The first vlan push only sets a\nhwaccel tag; the next - clsact \"action vlan push\" or\nbpf_skb_vlan_push() - enters the helper with skb-\u003elen still 1.  The\nhead comes from skbuff_small_head without __GFP_ZERO, so each push\ndrags bytes from beyond skb-\u003etail into the frame.  After three the\none-byte send leaves as 13 bytes carrying 11 bytes of uninitialised\nslab:\n\n  0000: 5a b3 62 12 80 88 ff ff 00 b3 62 12 81\n           `------------------------------'\n  only 0x5a was sent; the rest is slab, here the top 56 bits of a\n  linear-map address\n\nRequire the MAC header the helper rewrites to be present, so such a\nframe is dropped rather than transmitted.",
  "id": "CVE-2026-98377",
  "modified": "2026-10-11T02:30:37.407258120Z",
  "published": "2026-10-09T07:34:17.832Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/40a5cc4b7251c74f3341332a226d02200e96bccf"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/59af43ccece4d2d8b62e9e3ccc96b6e2e793bcdc"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/ab888242fce4f16f6c4d4c6ec53939ad36aa3b3a"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/f42562dd027dc4ed103fae17b2206e73ea1963c4"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98377.json"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-98377"
    },
    {
      "type": "PACKAGE",
      "url": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"
    }
  ],
  "schema_version": "1.9.0",
  "summary": "vlan: require the MAC header to be present in __vlan_insert_inner_tag()"
}