CVE-2026-80906

    Dashboard / Vulnerabilities / CVE-2026-80906

    CVE-2026-80906

    Published: 4 Sept 2026Last Modified: 6 Sept 2026

    Summary: net: packet: fix wrong transport_header when sending VLAN-tagged frame

    Details: In the Linux kernel, the following vulnerability has been resolved: net: packet: fix wrong transport_header when sending VLAN-tagged frame In packet_parse_headers(), when processing a VLAN-tagged frame, skb_set_network_header() is called to advance network_header past the VLAN tag to the inner protocol header. skb_probe_transport_header() is then called with skb->protocol still set to the outer VLAN EtherType (e.g. ETH_P_8021Q), while nhoff (derived from skb_network_offset()) already points past the VLAN tag to the inner protocol header. In __skb_flow_dissect(), proto is initialized to ETH_P_8021Q and nhoff points past the VLAN tag. When the dissector hits case ETH_P_8021Q, it reads a struct vlan_hdr at nhoff via __skb_header_pointer(), but that offset contains the inner protocol header (e.g. an IP header). The bytes are misinterpreted as a VLAN header, yielding a garbage encapsulated EtherType that matches no known protocol. The dissector returns false, so skb_probe_transport_header() never calls skb_set_transport_header(), leaving transport_header at its uninitialized sentinel value (~0U). Move skb_probe_transport_header() to before skb_set_network_header(). At the time skb_probe_transport_header() is called, network_header still points to the VLAN header, so nhoff correctly points to the VLAN header. The flow dissector can then parse the VLAN header, extract the inner EtherType, and advance nhoff to the inner protocol header, allowing transport_header to be set correctly.

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Introduced- c2137d565ceb505de69593c181a0543bc4083838

    Affected versions

    v5.10.265
    v5.10.264
    v5.10.263
    v5.10.262
    v5.10.261
    v5.10.260
    v5.10.259
    v5.10.258
    v5.10.257
    v5.10.256
    v5.10.255
    v5.10.254
    v5.10.253
    v5.10.252
    v5.10.251
    v5.10.250
    v5.10.249
    v5.10.248
    v5.10.247
    v5.10.246
    v5.10.245
    v5.10.244
    v5.10.243
    v5.10.242
    v5.10.241
    v5.10.240
    v5.10.239
    v5.10.238
    v5.10.237
    v5.10.236
    v5.10.235
    v5.10.234
    v5.10.233
    v5.10.232
    v5.10.231
    v5.10.230
    v5.10.229
    v5.10.228
    v5.10.227
    v5.10.226
    v5.10.225
    v5.10.224
    v5.10.223
    v5.10.222
    v5.10.221
    v5.10.220
    v5.10.219
    v5.10.218
    v5.10.217
    v5.10.216
    v5.10.215
    v5.10.214
    v5.10.213
    v5.10.212
    v5.10.211
    v5.10.210
    v5.10.209
    v5.10.208
    v5.10.207
    v5.10.206
    v5.10.205
    v5.10.204
    v5.10.203
    v5.10.202
    v5.10.201
    v5.10.200
    v5.10.199
    v5.10.198
    v5.10.197
    v5.10.196
    v5.10.195
    v5.10.194
    v5.10.193
    v5.10.192
    v5.10.191
    v5.10.190
    v5.10.189
    v5.10.188
    v5.10.187
    v5.10.186
    v5.10.185
    v5.10.184
    v5.10.183
    v5.10.182
    v5.10.181
    v5.10.180
    v5.10.179
    v5.10.178
    v5.10.177
    v5.10.176
    v5.10.175
    v5.10.174
    v5.10.173
    v5.10.172
    v5.10.171
    v5.10.170
    v5.10.169
    v5.10.168
    v5.10.167
    v5.10.166
    v5.10.165
    v5.10.164
    v5.10.163

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CVE-2026-80906 | CVE-DB