CVE-2026-80905
Last modified
CVE-2026-80905 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: net: tap: fix wrong transport_header when sending VLAN-tagged frame In tap_get_user_xdp(), when processing a VLAN-tagged frame (e.g. ETH_P_8021Q), skb_set_network_header() is called first to advance network_header past the VLAN tag to the inner protocol header. skb_probe_transport_header() is then called with skb->protocol still set to ETH_P_8021Q, while nhoff (derived from skb_network_offset()) already points past the VLAN tag to the inner protocol header. In __skb_flow_dissect(), proto is initialized to ETH_P_8021Q and nhoff points past the VLAN tag. When the dissector hits case ETH_P_8021Q, it reads a struct vlan_hdr at the current nhoff via __skb_header_pointer(), but that offset contains the inner protocol header (e.g.
Description
In the Linux kernel, the following vulnerability has been resolved: net: tap: fix wrong transport_header when sending VLAN-tagged frame In tap_get_user_xdp(), when processing a VLAN-tagged frame (e.g. ETH_P_8021Q), skb_set_network_header() is called first to advance network_header past the VLAN tag to the inner protocol header. skb_probe_transport_header() is then called with skb->protocol still set to ETH_P_8021Q, while nhoff (derived from skb_network_offset()) already points past the VLAN tag to the inner protocol header. In __skb_flow_dissect(), proto is initialized to ETH_P_8021Q and nhoff points past the VLAN tag. When the dissector hits case ETH_P_8021Q, it reads a struct vlan_hdr at the current nhoff via __skb_header_pointer(), but that offset contains the inner protocol header (e.g. an IP header). The bytes are misinterpreted as a VLAN header, yielding a garbage encapsulated EtherType that matches no known protocol. The dissector returns false, so skb_probe_transport_header() never calls skb_set_transport_header(), leaving transport_header at its uninitialized sentinel value (~0U). Move skb_set_network_header() to after skb_probe_transport_header(). At the time skb_probe_transport_header() is called, network_header still points to the VLAN header (offset ETH_HLEN), so nhoff is correct and the flow dissector can parse the VLAN header, extract the inner EtherType, and advance nhoff to the inner protocol header, allowing transport_header to be set correctly.
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 8c76e77f9069f10505c08e02646c3ee11ad79038, < 5ffaa5d7f56ab24a8e23cf131eadfef31a3bbc4b; >= 8c76e77f9069f10505c08e02646c3ee11ad79038, < 88b79ac89ecc04d7f2613f7e1c0b46f0c4ddb2f3; >= 8c76e77f9069f10505c08e02646c3ee11ad79038, < cbb35cbe8db268fefe34c23df15348cf99025298; 3cae5ef1f37a475faf7c40bc6a3c170779f3e0b1; >= 4.20.1, < 4.21 |
| Linux | Linux | 5.0 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-80905?
How severe is CVE-2026-80905?
How do I fix CVE-2026-80905?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-8090Use-after-free in the DOM: Networking component. This vulner…7.3
- CVE-2026-80900In the Linux kernel, the following vulnerability has been re…
- CVE-2026-80901In the Linux kernel, the following vulnerability has been re…
- CVE-2026-80902In the Linux kernel, the following vulnerability has been re…
- CVE-2026-80903In the Linux kernel, the following vulnerability has been re…
- CVE-2026-80904In the Linux kernel, the following vulnerability has been re…
- CVE-2026-80906In the Linux kernel, the following vulnerability has been re…
- CVE-2026-80907In the Linux kernel, the following vulnerability has been re…
- CVE-2026-80908In the Linux kernel, the following vulnerability has been re…
- CVE-2026-80909In the Linux kernel, the following vulnerability has been re…
- CVE-2026-8091Incorrect boundary conditions in the Audio/Video: Playback c…9.8
- CVE-2026-80910In the Linux kernel, the following vulnerability has been re…
Are you affected by CVE-2026-80905?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
