天下漏洞,尽知其名
HIGH

CVE-2026-98377 Linux 内核 vlan 越界写入漏洞

影响可越界写入并泄露内核未初始化内存数据

AI 研判

Linux 内核 vlan 子系统中 __vlan_insert_inner_tag() 仅通过 skb_cow_head() 保证头部空间,却未校验 MAC 头(mac_len)是否真实存在。在 IFF_TUN 等 hard_header_len 为 0 的设备上,配合 AF_PACKET/SOCK_RAW 短帧及 vlan push 操作,会触发对 skb->data 起始 16 字节的越界重写。

影响范围

Linux Kernel

受影响范围为包含该缺陷代码的 Linux 内核版本,具体版本区间暂无公开信息,需以官方补丁 commit 为准。

漏洞详情

漏洞类型为越界写入(out-of-bounds write)。成因是 __vlan_insert_inner_tag() 及其 ETH_HLEN 包装函数在插入 VLAN 标签时,未像 pop 路径那样使用 skb_ensure_writable()/pskb_may_pull() 校验 MAC 头长度,直接对 skb->data 前 16 字节做 memmove 和两次 2 字节写入。攻击者可通过 IFF_TUN 设备发送单字节 AF_PACKET/SOCK_RAW 帧,再经 clsact "action vlan push" 或 bpf_skb_vlan_push() 多次触发,将 skb->tail 之后的未初始化 slab 数据拖入帧中。

利用条件与风险

利用前提是本地具备发送 AF_PACKET 原始帧及触发 vlan push 的能力(如具备相应权限或处于特定网络命名空间)。实战中可造成内核内存越界写入与信息泄露,存在提权或信息泄露风险。

修复建议

官方已通过要求 MAC 头存在的补丁修复该漏洞,建议升级到包含该修复的内核版本。临时缓解措施暂无公开信息。

原始情报

In the Linux kernel, the following vulnerability has been resolved:

vlan: require the MAC header to be present in __vlan_insert_inner_tag()

__vlan_insert_inner_tag() only guarantees head room via skb_cow_head(),
never that mac_len bytes of MAC header are present. Its ETH_HLEN
wrappers – __vlan_insert_tag() under skb_vlan_push(), and
vlan_insert_tag() under validate_xmit_vlan() on the generic transmit
path – therefore rewrite the first 16 bytes at skb->data: a 12-byte
memmove plus two 2-byte stores at +12 and +14. No caller supplies the
bound, while the pop helpers use skb_ensure_writable()/pskb_may_pull().

An IFF_TUN device has hard_header_len == 0, so packet_snd() accepts a
one-byte AF_PACKET/SOCK_RAW frame. The first vlan push only sets a
hwaccel tag; the next – clsact “action vlan push” or
bpf_skb_vlan_push() – enters the helper with skb->len still 1. The
head comes from skbuff_small_head without __GFP_ZERO, so each push
drags bytes from beyond skb->tail into the frame. After three the
one-byte send leaves as 13 bytes carrying 11 bytes of uninitialised
slab:

0000: 5a b3 62 12 80 88 ff ff 00 b3 62 12 81
`——————————‘
only 0x5a was sent; the rest is slab, here the top 56 bits of a
linear-map address

Require the MAC header the helper rewrites to be present, so such a
frame is dropped rather than transmitted.