SB20260919101 - Signed to Unsigned Conversion Error in Linux kernel bridge
Published: September 19, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Signed to Unsigned Conversion Error (CVE-ID: CVE-2026-90114)
CWE-ID: CWE-195 - Signed to Unsigned Conversion Error
CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause unpredictable request return values.
The vulnerability exists due to an incorrect signed-to-unsigned conversion in br_process_vlan_tunnel_info when processing bridge VLAN tunnel range requests. A local user can submit a bridge VLAN tunnel range with descending VLAN IDs to cause unpredictable request return values.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/0874a6d5275091429ec4c675c54c53a8776665ae
- https://git.kernel.org/stable/c/1181f6bad009408a259bab6aaf0681f11b487972
- https://git.kernel.org/stable/c/434849b21ef56b09d16e6366b2a230002f363e45
- https://git.kernel.org/stable/c/4b0f5b25f114651f03058395b490626c4444875e
- https://git.kernel.org/stable/c/5a8e0e3a18b5e3172343b8479c5d04187f5b4795
- https://git.kernel.org/stable/c/b74a072d8fb71d3c9ffba4a17d5943e63266fb38
- https://git.kernel.org/stable/c/bd741b819ff1c239d26cc5b0f0e6b1fd4e67ed17
- https://git.kernel.org/stable/c/c0444d7499f113d6b7803ef0175591464e17525e