{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  net/sched: act_skbmod: fix length calculations and avoid invalid header warnings  syzbot reported a warning in skb_network_header_len() triggered by tcf_skbmod_act():    !skb_transport_header_was_set(skb)   WARNING: CPU: 0 PID: 14949 at include/linux/skbuff.h:3243 skb_network_header_len include/linux/skbuff.h:3243 [inline]   WARNING: CPU: 0 PID: 14949 at net/sched/act_skbmod.c:55 tcf_skbmod_act+0xfe8/0x1810 net/sched/act_skbmod.c:55  There are a few issues in tcf_skbmod_act():  1. Calling skb_network_header_len() assumes skb-\u003etransport_header is set,    which is not guaranteed when tcf_skbmod_act() runs at TC ingress. 2. Unconditionally calling skb_mac_header_len() at the beginning of    tcf_skbmod_act() triggers a warning on L3 devices (e.g. TUN) where the    MAC header is unset, evaluating to an underflowed garbage length. 3. On TC ingress, skb-\u003edata points to the network header. Adding the MAC    header length to the IP header length causes skb_ensure_writable() to    request more bytes than the actual IP packet length, dropping valid    short packets (e.g. 28-byte UDP/IPv4 packets).  Fix these by: - Using skb_network_offset(skb) + sizeof(struct iphdr/ipv6hdr) for   SKBMOD_F_ECN so that the required length is correctly calculated on   both ingress (offset == 0) and egress (offset == mac_len). - Setting max_edit_len to ETH_HLEN for Ethernet header modifications   after validating ARPHRD_ETHER.",
  "id": "DEBIAN-CVE-2026-90078",
  "modified": "2026-09-18T04:47:26.247226900Z",
  "published": "2026-09-17T17:16:57.057Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-90078"
    }
  ],
  "upstream": [
    "CVE-2026-90078"
  ]
}