Integer underflow in Linux kernel - CVE-2026-90078
Published: September 19, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper length calculation in tcf_skbmod_act() when processing short IP packets at TC ingress. A remote attacker can send a short IP packet to cause a denial of service.
Exploitation requires the skbmod action to process ECN modifications at TC ingress.
Affected software
How to mitigate CVE-2026-90078
External References
- https://git.kernel.org/stable/c/0675cff3c2924eb9b80d9dd250cf56a1140af157
- https://git.kernel.org/stable/c/1719865b20b22c88d2a55e922eff5ca31b0841f6
- https://git.kernel.org/stable/c/62126464f3a6159c0a3dd89e196ba65bfeb0afc6
- https://git.kernel.org/stable/c/81d0d1e64f30d9989c829c0953cd6e6c68d9c5fb
- https://git.kernel.org/stable/c/985a37781ade19061400100c2ba0f43979dd4d63
- https://git.kernel.org/stable/c/d896843d8d925f0adbba319020595cfb1a7bcd57
- https://git.kernel.org/stable/c/e8a2027b7e686784a69b2dfcee841d779919f313