Kestrel
대시보드로 돌아가기
CVE-2026-90078UNKNOWNMITRENVD대응게시일: 2026. 09. 17.수정일: 2026. 09. 17.CNA: 416baaa9-dc9f-4396-8d5f-8c081fb06d67Received

In the Linux kernel, the following vulnerability has been resolved: net/sched: act_skbmod: fix length calculations and avoid invalid header

위협 신호 · CVSS · EPSS · KEV

정기 패치· 높은 악용 신호 없음
CVSS
unknown

이론적 심각도 점수

EPSS

예측 데이터 없음

KEV
미등재

실측 악용 기록 없음

권장 대응 기한60일 이내CISA SSVC 기준

계획된 패치 주기 내 조치(60일 이내)

외부 노출· KEV 미등재 · 자동화 어려움 · 부분 영향 · 외부 노출

CVSS 벡터 · 메트릭

CVSS 벡터 정보 없음

상세 설명

In the Linux kernel, the following vulnerability has been resolved:

net/sched: act_skbmod: fix length calculations and avoid invalid header warnings

syzbot reported a warning in skb_network_header_len() triggered
by tcf_skbmod_act():

!skb_transport_header_was_set(skb)
WARNING: CPU: 0 PID: 14949 at include/linux/skbuff.h:3243 skb_network_header_len include/linux/skbuff.h:3243 [inline]
WARNING: CPU: 0 PID: 14949 at net/sched/act_skbmod.c:55 tcf_skbmod_act+0xfe8/0x1810 net/sched/act_skbmod.c:55

There are a few issues in tcf_skbmod_act():

  1. Calling skb_network_header_len() assumes skb->transport_header is set,
    which is not guaranteed when tcf_skbmod_act() runs at TC ingress.
  2. Unconditionally calling skb_mac_header_len() at the beginning of
    tcf_skbmod_act() triggers a warning on L3 devices (e.g. TUN) where the
    MAC header is unset, evaluating to an underflowed garbage length.
  3. On TC ingress, skb->data points to the network header. Adding the MAC
    header length to the IP header length causes skb_ensure_writable() to
    request more bytes than the actual IP packet length, dropping valid
    short packets (e.g. 28-byte UDP/IPv4 packets).

Fix these by:

  • Using skb_network_offset(skb) + sizeof(struct iphdr/ipv6hdr) for
    SKBMOD_F_ECN so that the required length is correctly calculated on
    both ingress (offset == 0) and egress (offset == mac_len).
  • Setting max_edit_len to ETH_HLEN for Ethernet header modifications
    after validating ARPHRD_ETHER.

AI 심층 분석

공격 시나리오 · 재현 가능한 PoC 페이로드 · 즉시 적용 가능한 차단 패치를 한 번에 받아 보세요. 보안 운영팀이 그대로 점검·티켓팅에 쓸 수 있는 형태로 정리해 드립니다.