Incorrect behavior order in Linux kernel - CVE-2026-80906
Published: September 5, 2026
Vulnerability identifier: #VU147003
CSH Severity: Low
CVSS v4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-80906
CWE-ID: CWE-696
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to cause incorrect transport header handling.
The vulnerability exists due to incorrect behavior order in packet_parse_headers() when processing a VLAN-tagged frame. A remote attacker can send a VLAN-tagged frame to cause incorrect transport header handling.
Affected software
Linux kernel
How to mitigate CVE-2026-80906
Install security update from vendor's repository.
External References
- https://git.kernel.org/stable/c/01fdecc0480d916c799dbee584833a4a37e94d06
- https://git.kernel.org/stable/c/5479eb9b355f44745d7ccfe112386bd4f96eceea
- https://git.kernel.org/stable/c/6386a6ffa2efba2965ed8e4fa303582c0b76a215
- https://git.kernel.org/stable/c/6971cf319263d6a1b4096f9248aca9e57d77a1eb
- https://git.kernel.org/stable/c/a4b82de96d465ddb44bc931145c0fa80c4fe9c9c
- https://git.kernel.org/stable/c/e451e20adb869a983a21dda158625f024142e61f
- https://git.kernel.org/stable/c/f9297abbcaba760b7a7b9d63b839f607f738013e
- https://git.kernel.org/stable/c/fa86bc52ea8ba981f74f851fd61e2a3d3bc0feac