CVE-2026-90078

Source
https://cve.org/CVERecord?id=CVE-2026-90078
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90078.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-90078
Downstream
Published
2026-09-17T16:05:56Z
Modified
2026-09-19T03:47:23Z
Summary
net/sched: act_skbmod: fix length calculations and avoid invalid header warnings
Details

In the Linux kernel, the following vulnerability has been resolved:

net/sched: act_skbmod: fix length calculations and avoid invalid header warnings

syzbot reported a warning in skb_network_header_len() triggered by tcf_skbmod_act():

!skb_transport_header_was_set(skb) WARNING: CPU: 0 PID: 14949 at include/linux/skbuff.h:3243 skb_network_header_len include/linux/skbuff.h:3243 [inline] WARNING: CPU: 0 PID: 14949 at net/sched/act_skbmod.c:55 tcf_skbmod_act+0xfe8/0x1810 net/sched/act_skbmod.c:55

There are a few issues in tcf_skbmod_act():

  1. Calling skb_network_header_len() assumes skb->transport_header is set, which is not guaranteed when tcf_skbmod_act() runs at TC ingress.
  2. Unconditionally calling skb_mac_header_len() at the beginning of tcf_skbmod_act() triggers a warning on L3 devices (e.g. TUN) where the MAC header is unset, evaluating to an underflowed garbage length.
  3. On TC ingress, skb->data points to the network header. Adding the MAC header length to the IP header length causes skb_ensure_writable() to request more bytes than the actual IP packet length, dropping valid short packets (e.g. 28-byte UDP/IPv4 packets).

Fix these by:

  • Using skb_network_offset(skb) + sizeof(struct iphdr/ipv6hdr) for SKBMOD_F_ECN so that the required length is correctly calculated on both ingress (offset == 0) and egress (offset == mac_len).
  • Setting max_edit_len to ETH_HLEN for Ethernet header modifications after validating ARPHRD_ETHER.
Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/90xxx/CVE-2026-90078.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
56af5e749f20c3a540310c207dcc373f4f09156e
Fixed
985a37781ade19061400100c2ba0f43979dd4d63
Fixed
d896843d8d925f0adbba319020595cfb1a7bcd57
Fixed
0675cff3c2924eb9b80d9dd250cf56a1140af157
Fixed
e8a2027b7e686784a69b2dfcee841d779919f313
Fixed
1719865b20b22c88d2a55e922eff5ca31b0841f6
Fixed
62126464f3a6159c0a3dd89e196ba65bfeb0afc6
Fixed
81d0d1e64f30d9989c829c0953cd6e6c68d9c5fb

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90078.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.15.0
Fixed
5.15.221
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.188
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.157
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.110
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.52
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90078.json"