VLAN Tag Processing Vulnerability in Linux Kernel
CVE-2026-80906
What is CVE-2026-80906?
A vulnerability exists in the Linux kernel's handling of VLAN-tagged frames during packet processing. When processing a VLAN-tagged frame, the network header is incorrectly set, which leads to misinterpretation of the encapsulated EtherType. This issue occurs due to the order of function calls that advance pointers in the packet structure, resulting in the transport header remaining uninitialized. The flaw could lead to errors in packet dissection, impacting the handling of network traffic. A fix has been implemented to rearrange the processing sequence, allowing for accurate reading of the VLAN header and correct advancement to the inner protocol header.
Affected Version(s)
Linux c2137d565ceb505de69593c181a0543bc4083838
Linux 9ff46c36df2e0a1ac352f2f4038eaf3f0f7361b8
Linux dfed913e8b55a0c2c4906f1242fd38fd9a116e49 < 5479eb9b355f44745d7ccfe112386bd4f96eceea