SB2026100773 - Numeric Truncation Error in Linux kernel stmicro stmmac driver
Published: October 7, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Numeric Truncation Error (CVE-ID: CVE-2026-98288)
CWE-ID: CWE-197 - Numeric Truncation Error
CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause protocol header lengths to be truncated during TCP segmentation offload.
The vulnerability exists due to numeric truncation in stmmac_tso_xmit() when processing TCP over IPv6 packets with protocol headers longer than 255 bytes. A local user can create a TCP over IPv6 socket with several hundred bytes of sticky destination or hop-by-hop options to cause protocol header lengths to be truncated during TCP segmentation offload.
The packet validation function accepts protocol headers up to 1023 bytes, allowing these packets to reach the affected transmit function.
Remediation
Install update from vendor's website.