{"id":"AZL-106896","summary":"CVE-2026-98377 affecting package kernel 6.6.157.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nvlan: require the MAC header to be present in __vlan_insert_inner_tag()\n\n__vlan_insert_inner_tag() only guarantees head room via skb_cow_head(),\nnever that mac_len bytes of MAC header are present.  Its ETH_HLEN\nwrappers - __vlan_insert_tag() under skb_vlan_push(), and\nvlan_insert_tag() under validate_xmit_vlan() on the generic transmit\npath - therefore rewrite the first 16 bytes at skb-\u003edata: a 12-byte\nmemmove plus two 2-byte stores at +12 and +14.  No caller supplies the\nbound, while the pop helpers use skb_ensure_writable()/pskb_may_pull().\n\nAn IFF_TUN device has hard_header_len == 0, so packet_snd() accepts a\none-byte AF_PACKET/SOCK_RAW frame.  The first vlan push only sets a\nhwaccel tag; the next - clsact \"action vlan push\" or\nbpf_skb_vlan_push() - enters the helper with skb-\u003elen still 1.  The\nhead comes from skbuff_small_head without __GFP_ZERO, so each push\ndrags bytes from beyond skb-\u003etail into the frame.  After three the\none-byte send leaves as 13 bytes carrying 11 bytes of uninitialised\nslab:\n\n  0000: 5a b3 62 12 80 88 ff ff 00 b3 62 12 81\n           `------------------------------'\n  only 0x5a was sent; the rest is slab, here the top 56 bits of a\n  linear-map address\n\nRequire the MAC header the helper rewrites to be present, so such a\nframe is dropped rather than transmitted.","modified":"2026-10-10T14:17:32.475460788Z","published":"2026-10-09T08:16:56Z","upstream":["CVE-2026-98377"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-98377"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.157.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-106896.json"}}],"schema_version":"1.9.0"}