๐Ÿ” CVE Alert

CVE-2026-98241

UNKNOWN 0.0

ipv6: xfrm: use full sockets in local error paths

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: ipv6: xfrm: use full sockets in local error paths xfrm6_local_rxpmtu() and xfrm6_local_error() dereference skb->sk as if it always pointed at a full IPv6 socket. That is not guaranteed. TCP SYN-ACK skbs can be owned by a TCP_NEW_SYN_RECV request_sock while the output path itself is driven by the full listener. If rerouting selects an IPv6 XFRM tunnel route with a lower MTU, the local PMTU/error handling path can reach these callbacks with that mini-socket still attached to the skb. The callbacks then miscast the request socket as a full inet/IPv6 socket and can read beyond the request_sock allocation when they access inet_sock or ipv6_pinfo state. Resolve the owner with skb_to_full_sk() in both callbacks and bail out when no full socket is attached. This matches the surrounding XFRM IPv6 PMTU/error logic, which already reasons about full sockets with skb_to_full_sk().

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Oct 6, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
dd767856a36e00b631d65ebc4bb81b19915532d6 < b1a88633c36d2cbc3831382f3846754d344276fd dd767856a36e00b631d65ebc4bb81b19915532d6 < 904a0e827d0d7189271a3a2eb648293809f25efc dd767856a36e00b631d65ebc4bb81b19915532d6 < 675919e08ce266b8cac11fd9af29170e762a480f dd767856a36e00b631d65ebc4bb81b19915532d6 < 60459c670329d586a58db5d8f811fa5accfe4862 dd767856a36e00b631d65ebc4bb81b19915532d6 < ca3d68c3213475b53db6647e159dc73bd1af5ab1 dd767856a36e00b631d65ebc4bb81b19915532d6 < 4c030a0400ebfd2318361c923a88103b2c67c49f dd767856a36e00b631d65ebc4bb81b19915532d6 < c21f3f7fbfeda7c5794f606cb0ffcc2d9001eef8 dd767856a36e00b631d65ebc4bb81b19915532d6 < 6973a21ee73c5567f883813c8ef414774b45892f
Linux / Linux
3.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/b1a88633c36d2cbc3831382f3846754d344276fd git.kernel.org: https://git.kernel.org/stable/c/904a0e827d0d7189271a3a2eb648293809f25efc git.kernel.org: https://git.kernel.org/stable/c/675919e08ce266b8cac11fd9af29170e762a480f git.kernel.org: https://git.kernel.org/stable/c/60459c670329d586a58db5d8f811fa5accfe4862 git.kernel.org: https://git.kernel.org/stable/c/ca3d68c3213475b53db6647e159dc73bd1af5ab1 git.kernel.org: https://git.kernel.org/stable/c/4c030a0400ebfd2318361c923a88103b2c67c49f git.kernel.org: https://git.kernel.org/stable/c/c21f3f7fbfeda7c5794f606cb0ffcc2d9001eef8 git.kernel.org: https://git.kernel.org/stable/c/6973a21ee73c5567f883813c8ef414774b45892f