Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

CVE-2026-80634

netfilter: flowtable: avoid num_encaps underflow on bridge VLAN untag
Back to all
CVE

CVE-2026-80634

netfilter: flowtable: avoid num_encaps underflow on bridge VLAN untag

In the Linux kernel, the following vulnerability has been resolved:

netfilter: flowtable: avoid num_encaps underflow on bridge VLAN untag

The DEVPATHBRVLANUNTAG case post-decrements info->num_encaps

inside WARNONONCE(). num_encaps is u8, so if it's already 0 the

decrement still happens and wraps it to 255. The break only leaves

the inner switch -- a later path entry can set info->indev back to

a real device, and we end up returning with num_encaps == 255.

nftdevforward_path() then walks info.encap[] (size 2) up to

num_encaps, which means an OOB stack read and a bogus count copied

into the route descriptor.

Should only happen on a malformed bridge path stack, hence the WARN,

but worth handling sanely. Move the decrement out of the WARN.

[ While at this, remove the WARNONONCE since this can only happen

  with a buggy bridge path stack --pablo ].

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
9.8
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
0
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
-

Related Resources

No items found.

References

https://git.kernel.org/stable/c/2f55fa28011c97d6495d5787808db10a8c2d690d, https://git.kernel.org/stable/c/e052f920773b73be49eb4d8702a9f85de7464363, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80634.json, https://nvd.nist.gov/vuln/detail/CVE-2026-80634, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Severity

9.8

CVSS Score
0
10

Basic Information

Base CVSS
9.8
EPSS Probability
0.00553%
EPSS Percentile
0.4447%
Introduced Version
e990cef6516daa4e1e236433579e333f74fd38cb,5.13.0,0
Fix Available
e052f920773b73be49eb4d8702a9f85de7464363,7.1.5,7.0.0-38.38,7.0.0-1014.14,7.0.0-1017.17,7.0.0-1016.16,7.0.0-1008.9,7.0.0-1015.15,7.0.0-1013.13,7.0.0-38.38.1

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading