Out-of-bounds write in Linux kernel - CVE-2026-98158
Published: September 28, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper handling of skb headroom in ppp_async's process_input_packet() when processing a bad-FCS PPP frame followed by a crafted frame. A remote attacker can send malformed PPP frames to cause a denial of service.
When CCP compression is enabled, decompression can read before the skb head.