SB2026090523 - Incorrect behavior order in Linux kernel packet
Published: September 5, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Incorrect behavior order (CVE-ID: CVE-2026-80906)
CWE-ID: CWE-696 - Incorrect Behavior Order
CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause incorrect transport header handling.
The vulnerability exists due to incorrect behavior order in packet_parse_headers() when processing a VLAN-tagged frame. A remote attacker can send a VLAN-tagged frame to cause incorrect transport header handling.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/01fdecc0480d916c799dbee584833a4a37e94d06
- https://git.kernel.org/stable/c/5479eb9b355f44745d7ccfe112386bd4f96eceea
- https://git.kernel.org/stable/c/6386a6ffa2efba2965ed8e4fa303582c0b76a215
- https://git.kernel.org/stable/c/6971cf319263d6a1b4096f9248aca9e57d77a1eb
- https://git.kernel.org/stable/c/a4b82de96d465ddb44bc931145c0fa80c4fe9c9c
- https://git.kernel.org/stable/c/e451e20adb869a983a21dda158625f024142e61f
- https://git.kernel.org/stable/c/f9297abbcaba760b7a7b9d63b839f607f738013e
- https://git.kernel.org/stable/c/fa86bc52ea8ba981f74f851fd61e2a3d3bc0feac