Signed to Unsigned Conversion Error in Linux kernel - CVE-2026-90114
Published: September 19, 2026
Vulnerability details
The vulnerability allows a local user to cause unpredictable request return values.
The vulnerability exists due to an incorrect signed-to-unsigned conversion in br_process_vlan_tunnel_info when processing bridge VLAN tunnel range requests. A local user can submit a bridge VLAN tunnel range with descending VLAN IDs to cause unpredictable request return values.
Affected software
How to mitigate CVE-2026-90114
External References
- https://git.kernel.org/stable/c/0874a6d5275091429ec4c675c54c53a8776665ae
- https://git.kernel.org/stable/c/1181f6bad009408a259bab6aaf0681f11b487972
- https://git.kernel.org/stable/c/434849b21ef56b09d16e6366b2a230002f363e45
- https://git.kernel.org/stable/c/4b0f5b25f114651f03058395b490626c4444875e
- https://git.kernel.org/stable/c/5a8e0e3a18b5e3172343b8479c5d04187f5b4795
- https://git.kernel.org/stable/c/b74a072d8fb71d3c9ffba4a17d5943e63266fb38
- https://git.kernel.org/stable/c/bd741b819ff1c239d26cc5b0f0e6b1fd4e67ed17
- https://git.kernel.org/stable/c/c0444d7499f113d6b7803ef0175591464e17525e