๐Ÿ” CVE Alert

CVE-2026-98299

UNKNOWN 0.0

tcp: do not let tcp_rmem be set below 4096

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: tcp: do not let tcp_rmem be set below 4096 We can hit a division by zero crash in tcp_rcvbuf_grow() and tcp_rcv_space_adjust(): divide error: 0000 [#1] PREEMPT SMP RIP: 0010:tcp_rcvbuf_grow+0x187/0x450 net/ipv4/tcp_input.c:939 ... grow = div_u64(((u64)rcvwin << 1) * (newval - oldval), oldval); The division uses oldval = tp->rcvq_space.space as divisor. When tp->rcvq_space.space is zero, this leads to a divide-by-zero exception. tp->rcvq_space.space is initialized in tcp_init_buffer_space(): tp->rcvq_space.space = min3(tp->rcv_ssthresh, tp->rcv_wnd, (u32)TCP_INIT_CWND * tp->advmss); If tcp_rmem[1] is configured to very small values (such as 1), sk->sk_rcvbuf is initialized to 1. Then tcp_full_space(sk), which computes (sk->sk_rcvbuf * scaling_ratio) >> 8, truncates to 0. This sets tp->window_clamp = 0, tp->rcv_ssthresh = 0, and tp->rcvq_space.space = 0. Later, when data arrives and DRS is invoked, tcp_rcvbuf_grow() divides by oldval == 0. Back in 2015, commit b1cb59cf2efe ("net: sysctl_net_core: check SNDBUF and RCVBUF for min length") ensured that net.core.rmem_default and net.core.rmem_max cannot be set below SOCK_MIN_RCVBUF. Similarly, SO_RCVBUF setsockopt enforces max_t(int, val * 2, SOCK_MIN_RCVBUF). However, net.ipv4.tcp_rmem still had .extra1 = SYSCTL_ONE, allowing arbitrarily small values. Because SOCK_MIN_RCVBUF depends on sizeof(struct sk_buff) and cacheline alignment, its value varies across architectures and configuration options. Using a fixed constant of 4096 ensures a predictable, architecture- independent lower bound that is safely above SOCK_MIN_RCVBUF everywhere and matches the documented 4K default. Fix this by setting tcp_rmem.extra1 to 4096 and updating the documentation.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Oct 6, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 879907631b9e70eedb62d76461b29afa106ebe7a 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 8e32532d0fa3191ecf9524b0e6bafa0832e712ba 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 67b83c15bed9eeeb8d1a6dbf88a5f79525970173 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 9a4f49bf8d2da4e52e904f60c29cca317bab9b3a 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 60df201dbb19a1bf6478b56d100f7ae1fe90e46a 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 7898bda1ebc198f5559b301a96dd5398edd4d4d3 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 1c4bb940c3bb4325bb88ac1b7eaf5faaa39e7d63 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 83a945a529d6e002dd7339c532288a931f463dba
Linux / Linux
2.6.12

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/879907631b9e70eedb62d76461b29afa106ebe7a git.kernel.org: https://git.kernel.org/stable/c/8e32532d0fa3191ecf9524b0e6bafa0832e712ba git.kernel.org: https://git.kernel.org/stable/c/67b83c15bed9eeeb8d1a6dbf88a5f79525970173 git.kernel.org: https://git.kernel.org/stable/c/9a4f49bf8d2da4e52e904f60c29cca317bab9b3a git.kernel.org: https://git.kernel.org/stable/c/60df201dbb19a1bf6478b56d100f7ae1fe90e46a git.kernel.org: https://git.kernel.org/stable/c/7898bda1ebc198f5559b301a96dd5398edd4d4d3 git.kernel.org: https://git.kernel.org/stable/c/1c4bb940c3bb4325bb88ac1b7eaf5faaa39e7d63 git.kernel.org: https://git.kernel.org/stable/c/83a945a529d6e002dd7339c532288a931f463dba