SB2026100773 - Numeric Truncation Error in Linux kernel stmicro stmmac driver



SB2026100773 - Numeric Truncation Error in Linux kernel stmicro stmmac driver

Published: October 7, 2026

Security Bulletin ID SB2026100773
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Information disclosure

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Numeric Truncation Error (CVE-ID: CVE-2026-98288)

CWE-ID: CWE-197 - Numeric Truncation Error

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause protocol header lengths to be truncated during TCP segmentation offload.

The vulnerability exists due to numeric truncation in stmmac_tso_xmit() when processing TCP over IPv6 packets with protocol headers longer than 255 bytes. A local user can create a TCP over IPv6 socket with several hundred bytes of sticky destination or hop-by-hop options to cause protocol header lengths to be truncated during TCP segmentation offload.

The packet validation function accepts protocol headers up to 1023 bytes, allowing these packets to reach the affected transmit function.


Remediation

Install update from vendor's website.