SB2026090423 - Improper input validation in Linux kernel packet
Published: September 4, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper input validation (CVE-ID: CVE-2026-80742)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to trigger a kernel warning.
The vulnerability exists due to improper input validation in tpacket_fill_skb() in the AF_PACKET subsystem when sending zero-byte packets through a TPACKET ring buffer. A local user can send a zero-byte packet through the TPACKET ring buffer to trigger a kernel warning.
The issue occurs on devices with no hard header.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/1fc70b3d513bafb16b17540178870ef46e81c0bb
- https://git.kernel.org/stable/c/3fa110f9e2ea96f567f2194c673c4bc327640111
- https://git.kernel.org/stable/c/6bcd76c134c55c697148acb5c0194e9666abdf84
- https://git.kernel.org/stable/c/7521e691c7c4f2231634c95053281ac888d1f452
- https://git.kernel.org/stable/c/80a702964467b998d254f16cc61c2c9a20540c9d
- https://git.kernel.org/stable/c/98c5914d6b7bd4b4675535908e57dea31f1efd6a
- https://git.kernel.org/stable/c/dde212f8622f5cb36223fff1ebd6e6f2a3dc61fe
- https://git.kernel.org/stable/c/f09ac5682f1bb67981fcb6ead4d3cfe439225876