{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  vlan: fix skb_under_panic and races when toggling HW VLAN offload  Toggling hardware VLAN TX offload (NETIF_F_HW_VLAN_CTAG_TX or NETIF_F_HW_VLAN_STAG_TX) on a lower device invokes vlan_transfer_features(), which dynamically changed vlandev-\u003ehard_header_len.  This causes two issues: 1. Lockless TX paths (e.g. packet_snd in af_packet.c, ip6_finish_output2)    read dev-\u003ehard_header_len without holding RTNL lock. Mutating    hard_header_len dynamically under RTNL creates a data race where upper    layers reserve insufficient headroom based on a stale hard_header_len,    resulting in skb_under_panic when vlan_dev_hard_header() is called. 2. In addition, vlan_transfer_features() updated hard_header_len without    updating header_ops, causing a mismatch between allocated headroom    and header creation.  Always setting dev-\u003ehard_header_len = real_dev-\u003ehard_header_len and dev-\u003eneeded_headroom = real_dev-\u003eneeded_headroom + VLAN_HLEN unconditionally ensures: - dev-\u003ehard_header_len remains 100% static and immutable at real_dev-\u003ehard_header_len,   eliminating all dynamic runtime updates and data races on hard_header_len. - Upper layers allocating skbs via LL_RESERVED_SPACE() will always reserve   sufficient headroom for software VLAN tag insertion (real_dev-\u003ehard_header_len +   real_dev-\u003eneeded_headroom + VLAN_HLEN). - vlandev inherits real_dev-\u003eneeded_tailroom so underlying trailer/padding/ICV   requirements are honored. - AF_PACKET SOCK_RAW network header offsets remain correctly aligned at   real_dev-\u003ehard_header_len. - vlan_header_ops is used unconditionally.  Note to stable teams: Make sure to backport these commits:  e16e960d55a4 (\"ipvlan: inherit needed_headroom and needed_tailroom from phy_dev\") cef51860becd (\"macvlan: inherit needed_headroom and needed_tailroom from lowerdev\")",
  "id": "DEBIAN-CVE-2026-80925",
  "modified": "2026-09-10T04:47:21.247926713Z",
  "published": "2026-09-09T17:17:47.763Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-80925"
    }
  ],
  "upstream": [
    "CVE-2026-80925"
  ]
}